CargoWise WebTracker — The Keys Were in the Cargo ↗
Credentials recoverable from a logistics platform's own tracking interface.
Bugs in web applications, APIs, and the software behind them.
Credentials recoverable from a logistics platform's own tracking interface.
Unauthenticated SQL injection reachable in Drupal core.
Reading arbitrary files pre-authentication, as root, on cPanel.
A full lab build and exploitation walkthrough for exposed Jolokia JMX endpoints: reflected XSS (CVE-2018-1000129), JNDI remote code execution via a rogue LDAP server (CVE-2018-1000130), and dumping the Java heap to recover credentials.
Directory brute-forcing a private bug bounty target turned up a world-readable .htpasswd whose descrypt hash, once cracked, opened four staging and development subdomains.
An XSS payload stored as a Google Cloud project name executed months later in the unfiltered project-deletion error message, earning a $5,000 VRP reward, plus the impact argument that got it past a self-XSS classification.
An in-scope Shopify POS endpoint exposed the card reader's firmware bundles, which unpack via binwalk, a dd carve at 0x202024 and jffs2dump into a JFFS2 root filesystem containing a salted MD5 root hash.
Proxying OS X Spotlight through Burp showed it shipping the user's latitude and longitude to api.smoot.apple.com on every search, with two ways to block the request.
PayPal's invoicing feature accepted .xml attachments, and an XHTML-namespaced script element inside the XML executed when the file was served back. Includes the exploitability argument needed to qualify it for a bounty.
A duplicated q parameter in PayPal's merchant directory let an injected payload break out of script context, producing a reflected XSS that PayPal patched within days.
mailroom.prezi.com concatenated the request path onto its own hostname when redirecting, so a request to /.attacker-domain sent victims to a lookalike attacker-controlled host.
A Firefox-only reflected XSS on wwwb.search.billmelater.com, achieved by closing out of a style attribute and injecting a fresh script element, which the vendor classified as out of scope.
Results from two weeks of a Kippo SSH honeypot in November 2014: roughly 4,000 brute-force attempts, 2,500 distinct credential pairs, and a source distribution dominated by hosts in China.
A stored XSS in PayPal's account name field, delivered to arbitrary users through invoices after bypassing the signup flow's security check by truncating the workflow URL to /webapps/.
A payload placed in the URL fragment reached a DOM sink on PayPal's main domain and executed; PayPal closed the report as a duplicate.
Google Tag Manager validated macro names in the web UI but not in the JSON container import path, so a payload smuggled through a file upload executed and earned a $5,000 bounty.
WP Live Chat Support, MyLiveChat and Provide Support all accepted stored cross-site scripting during a 2014 customer install.
Chrome resolves and executes a script URL written as http: followed by any number of backslashes. Firefox does not, and that difference can slip past pattern-matching XSS filters, closed by Chromium as wontfix.
A path traversal issue on Prezi's map.prezi.com subdomain, fixed within two days of reporting and rewarded with a $1,000 bounty.
A 2014 run through PayPal's bug bounty scope: seven confirmed issues across paypal.com, financing.paypal.com, apps.paypal.com and the paypal-*.com family, all closed as duplicate or invalid.
Reflected cross-site scripting across 160 German tax office websites, disclosed via heise.de and forwarded to CERT-Bund for coordinated remediation.
A public PHP 5.3.3-5.3.6 socket_connect exploit carrying a bind-TCP shell payload, dropped as an uploaded PHP file and located with an nmap sweep of ports 4000-4500.
Chaining a login-form SQL injection through sqlmap's --os-shell into a Linux 2.6.32 local root exploit to go from the 'nobody' user to full control of the server.
Pivoting from Yahoo's main A record to its ARIN netblock and sweeping all 260,000 addresses in the /14 for an exposed phpinfo.php.