Biscuit's Bug Bounty Playbook
CtrlK
  • 👋Introduction to Biscuit's Bug Bounty Playbook
  • Mains
    • 🧾Resume For Cyber Security Freshie
    • 📗Browser extension For Bug Bounty
    • 📀POC Videos YT Channel
    • 📺55 YouTube Channels To Learn Hacking
    • 👀Hackers to Follow on Social Media
      • Twitter
      • Medium
      • YouTube
      • GitHub
      • Discord Server
      • Security GitBooks
    • 🏅Learn The Basics
      • 🎖️Type Of Cyber Security
      • 🥈Common Job Roles
      • 🥉Get Started With InfoSec
      • ⚕️Best Bug Bounty Platform
      • 🗞️Best InfoSec Writeups Website
      • 🍪Hacking Books
      • 🥂CLI Commands
      • 💿Learn WSL
    • 👩‍💻Fun Programming Codes
    • 🔮Build your own Bug Bounty Methodology
    • 🎴Bug Bounty Checklist
    • 😼JS Analysis for Bug Bounty
  • 🟧Learn to Use Burp Suite
  • Learn Android Bug Bounty
    • 🎥Video Tutorials
  • ❤️YouTube Channels
  • 📰Bug Bounty Reports
  • 📚Blogs & Writeups
  • 🏹GitHub Repository
  • 👨‍👨‍👧Conference Talks
  • 🖨️Automated Scanners
  • ⚙️Intentionally Vulnerable Apps
  • 🎱Learn Drozer For Android Pentesting
  • 🪀Learn Frida For Android Pentesting
  • 🏈Bypassing Security Protections in APKs via Objection and Frida
  • 🪁Security Tools For Android Pentesting
  • 😼PIDCAT for Android Bug Bounty Logging
  • 🎹CLI Commands & Shortcuts
  • My Android Bug Bounty Lab Setup
  • Learn Thick Client Pentesting
    • 🟥Introduction Videos
  • 📑Introduction Articles
  • ✅Pentesting Checklist
  • 📚Bug Bounty Writeups
  • 🐞Thick Client Vulnerabilities
    • DLL Hijacking Basics
  • 🥼Intentionally vulnerable labs
  • 🛠️Tools for Thick Client Pentesting
  • 🏠Bug Bounty Programs with Thick Client Scope
  • 💵Paid Udemy Course
  • Bug Bounty Reports & Articles
    • 0️⃣Index
    • 1️⃣Takeover's (Accounts, Sub-domains, etc)
      • 🚡Sub Domain Takeover
      • 🚠Account Takeover
      • 🚟dependency confusion vulnerability
    • 2️⃣IDOR (Indirect Object Reference)
    • 3️⃣Leaks & Disclosure (PII, API Key, etc)
    • 4️⃣Open Redirects
    • 5️⃣Request Forgery (CSRF & SSRF)
      • 🟢CSRF
      • 🔴SSRF
    • 6️⃣Injections (HTML, XSS, etc)
      • 🟡XSS
      • 🟠HTML Injection
      • ⚫SQL Injection
      • 🟣CR/LF Injection
      • 🟢SSTI
      • 🔴Host Header Injection
      • 🔵CSV Injection
    • 7️⃣Broken Access Control & Broken Authentication
      • ⚙️File Upload Functionality
      • ⚙️Password Reset Functionality
      • ⚙️2FA Functionality
      • ⚙️Oauth Functionality
      • ⚙️Bypassing
      • ⚙️Misconfiguration
      • ⚙️Captcha Bypass
      • ⚙️Business Logic Flow
    • 8️⃣Web Socket
    • 9️⃣Miscellaneous Reports
    • 🔟IDN Homograph Attack
    • 🧻User-Role Management Issue
    • 0️Cloud
      • 🌩️AWS S3
    • 1️Low Hanging Fruits
    • 2️Cache Vulnerabilities
    • 3️DOS/DDOS
  • 4️Forced Browsing
  • 5️RCE
  • 6️OSINT
  • Bug Bounty Platforms
    • 🐛BugCrowd
    • 🐞HackerOne
    • 🐝Intigriti
    • 🐜Open Bug Bounty
  • Exploiting Technologies
    • 0️⃣Introduction
    • 1️⃣Wordpress
    • 2️⃣GraphQL API
    • 3️⃣IDOR Vulnerability
Powered by GitBook
On this page
  1. Bug Bounty Reports & Articles

1️Low Hanging Fruits

LogoWeblate disclosed on HackerOne: Old password can be new passwordHackerOne
LogoHow to Report DMARC Vulnerabilities Efficiently To Earn Bounties EasilyMedium
LogoWeblate disclosed on HackerOne: Weak password policyHackerOne
https://medium.com/@sangamahesh650/finding-a-easy-p3-bug-05b54f70e14cmedium.com
https://medium.com/@sangamahesh650/how-to-find-a-easy-bug-it-worth-100-7485f9bf638fmedium.com
LogoFinding a easy p3 bug | by loyalonlytoday - Freediumwww.freedium.cfd
LogoGitLab disclosed on HackerOne: EXIF metadata not stripped from JPG...HackerOne
LogoP4 bug’s and their POC steps | Part 1Medium
LogoP4 bug’s and their POC steps | Part 2Medium
LogoP4 bug’s and their POC steps | Part 3Medium
LogoP4 bug’s and their POC steps | Part 4Medium
LogoP4 bug’s and their POC steps | Part 5Medium
LogoP4 bug’s and their POC steps | Part 6Medium
LogoP4 bug’s and their POC steps | Part 7 | $Easy Money$Medium
PreviousAWS S3NextCache Vulnerabilities

Last updated 5 months ago