Day 1 = CORS bug on google's 404 page (rewarded)arrow-up-right
Day 2 = Google Bug bounty Clickjacking on Google paymentarrow-up-right
Day 3 = From P5 to P2 to 100 BXSSarrow-up-right
Day 4 = How a simple CSRF attack turned into a P1arrow-up-right
Day 5 = Disclose Private Dashboard Chart's name and data in Facebook Analyticsarrow-up-right
Day 6 = How I bought my way to subdomain takeover on tokopediaarrow-up-right
Day 7 = Touch ID authentication Bypass on evernote and dropbox iOS appsarrow-up-right
Day 1 = RFI LFI Writeuparrow-up-right
Day 2 = 2FA Bypass via logical rate limiting Bypassarrow-up-right
Day 3 = Long String DOSarrow-up-right
Day 4 = Exploiting a Race condition vulnerabililtyarrow-up-right
Day 5 = Exploiting an SSRF trials and tribulationsarrow-up-right
Day 6 = Tricky oracle SQLI situationarrow-up-right
Day 7 = Microsoft RCE bugbountyarrow-up-right
Day 1 = CORS misconfiguration leading to private information disclosurearrow-up-right
Day 2 = Google APIs Clickjacking worth 1337$arrow-up-right
Day 3 = Google Acquisition XSS (Apigee)arrow-up-right
Day 4 = How I exploited the json csrf with method override techniquearrow-up-right
Day 5 = Disclosing privately shared gaming clips of any userarrow-up-right
Day 6 = Subdomain Takeover via pantheonarrow-up-right
Day 7 = Oauth authentication bypass on airbnb acquistion using wierd 1 char open redirectarrow-up-right
Day 1 = My first LFIarrow-up-right
Day 2 = Bypass 2FA in a websitearrow-up-right
Day 3 = AIRDOSarrow-up-right
Day 4 = Race condition that could result to RCE a story with an apparrow-up-right
Day 5 = SSRF on PDF generatorarrow-up-right
Day 6 = Exploiting โGoogle BigQueryโ SQLIarrow-up-right
Day 7 = OTP bruteforce account takeoverarrow-up-right
Last updated 2 years ago