writeups.xyz writeups.xyz / Client-Side Enforcement of Server-Side Security

Title Vulnerabilities Programs Authors
The UI Slip I Hit 750$: UI Manipulation Leading to Unauthorized Permission Changes
$9240 Bounty in 30 days Hunt Challenge
Insecure Authentication Tokens leading to Account Takeover
How I get 1000$ bounty for Discovering Account Takeover in Android Application
How i Hacked Scopely with “Sign in with Google”
Security vs Compliance-Cloudflare Password Policy Restriction Bypass
Break the Logic: 5 Different Perspectives in Single Page (€1500)
Account Takeover by OTP bypass
Hacking into Admin Panel of U.S Federal government system C.A.R.S — without credentials.
Broken Access Control Leads To Change Of Admin Details
How the use of hidden form fields lead to Email verification bypass
DMCA.COM Hack, Full Disclosure (With Proof-of-Concept)
Unhiding the hidden
Hunting Android Application Bugs Using Android Studio.
Using Inspect Element to Bypass Security restrictions | Bug Bounty POC
How Inspect Element Got me a Bounty
Using Burp Suite match and replace settings to escalate your user privileges and find hidden features
Client side validation strikes again: PIN code bypass !