writeups.xyz writeups.xyz / Authentication Bypass

Title Vulnerabilities Programs Authors
CentreStack Disclosure
How I Found My First Bug in Android App
Exploiting Hardcoded Keys to achieve RCE in Yellowfin BI
Using 0days to Protect the United Nations
Centreon map vulnerability
YAFPC — Unauthenticated Remote Code Execution
CVE-2022-25026 & CVE-2022-25027: Vulnerabilities in Rocket TRUfusion Enterprise
Cacti: Unauthenticated Remote Code Execution
Authentication Bypass in Nexus manager (version 3.37.3–02)
How I found multiple critical bugs in Red Bull
0 click Facebook Account Takeover and Two-Factor Authentication Bypass
Better Make Sure Your Password Manager Is Secure
2FA Enabled Accounts Can Bypass Authentication & Access Account After Deactivation
Access Any Owner Account without Authentication (Auth bypass + 2FA bypass)
From Zero to Hero Part 1: Bypassing Intel DCM’s Authentication by Spoofing Kerberos and LDAP Responses (CVE-2022-33942)
Checkmk: Remote Code Execution by Chaining Multiple Bugs (1/3)
Accidental $70k Google Pixel Lock Screen Bypass
23000$ for Authentication Bypass & File Upload & Arbitrary File Overwrite
Google SSO misconfiguration leading to Account Takeover
FortiOS, FortiProxy, and FortiSwitchManager Authentication Bypass Technical Deep Dive (CVE-2022-40684)
How I Found A P1 Bug
Exploits Explained: 5 Unusual Authentication Bypass Techniques
My First Valid Bug “Bypass the Admin Panel”
How I was able to Bypass Philips Authentication
Account takeover worth $1000