Escalating Privileges With SSRF
This post is regarding my findings on Synack Red Team. The findings included a total of 4 SSRFs. One of them being a fully unauthenticated SSRF leading to high privileged account takeover.
Full Disclosure - DOM-based XSS And Failures In Bug Bounty Hunting
A writeup about my failures while doing bug bounty
Holiday Hunting With Aquatone
This blog is about my findings while on a workcation to Goa with my hacker friends.
Second Order XXE Exploitation
A writeup about my finding on Synack that was an XXE that allowed me to read local files stored on the web server.
NoSQL Injection in Plain Sight
A writeup about a recent NoSQL injection I found in Synack Red Team