writeups.xyz writeups.xyz / Information Disclosure

Title Vulnerabilities Programs Authors
PII at Your Fingertips: How I Stumbled Upon an Easy-to-Find Data Leakage Vulnerability @ Swisscom
Google Extensions (Awarded $18833.7)
Privilege Escalation In Ibm Spectrum Virtualize
Chained to hit: Discovering new vectors to gain remote and root access in SAP Enterprise Software
HackerOne redacted usernames disclosure in “Export as .pdf” feature
Thirteen Years On: Advancing the Understanding of IIS Short File Name (SFN) Disclosure!
How I was Able To Bypass The Admin Panel
Major Security Flaws in Popular QuickBlox Chat And Video Framework Expose Sensitive Data Of Millions
[REL] A Journey Into Hacking Google Search Appliance
Recon only bugs are sweet!
Getting email address of any HackerOne user worth $7,500
How Abusing AWS CloudFormation Led to a Total Takeover of an AWS Environment
How did I get 200$ with WordPress vulnerability!!!
Laravel debug mode left on at Zouikwatzeggen.nl leaks admin credentials & potentially submitted reports of improper behaviour at Amsterdam University Medical Centers
iOS App Pentesting and Security with Real-World Case Studies Part 2
Multiple Vulnerabilities in Fortra Globalscape EFT Administration Server [FIXED]
How I Unveiled a Critical Vulnerability: Exposing All Buyers’ Invoices PII with a Single Trick
PII Data Leakage and US$1500 Bounty
Hunting for Bitwarden master passwords stored in memory
How a misconfigured Lotus Domino Server can lead to Disclosure of PII Data of Employees, Configuration Details about the Active Directory, etc
Critical vulnerability on TP-Link service or how I got 0$
Find out the IP address through a call to Telegram…
Ericsson Sensitive Data Exposure via Trace.axd
Exposing iCloud user’s Name, phone numbers, and email addresses.
Why You Should Always Check The Audit Log [Medium] — $500