Open in app

Sign In

Write

Sign In

ag3n7
ag3n7

230 Followers

Home

About

Published in

System Weakness

·Pinned

How I bypassed Cloudflare WAF to get my First Bug

This blog is about how I found my first XSS vulnerability. — Hola Hackers, I am new to bug bounty and was trying to find my first bug, learning about vulnerabilities, etc these days. Along with learning, I tested websites for vulnerabilities like XSS(Cross-Site Scripting). Firstly I found a reflected XSS on a website. Respecting privacy let’s name the target as redacted.com. …

Cross Site Scripting

3 min read

How I bypassed Cloudflare WAF to get my First Bug
How I bypassed Cloudflare WAF to get my First Bug
Cross Site Scripting

3 min read


Published in

InfoSec Write-ups

·Feb 8

Chaining Bugs to get my First Bug Bounty

Openredirection + clickjacking + csrf -> Account Takeover Hola Hackers, This writeup is about my first bug bounty in which the submission was duplicate, even though they rewarded me for chaining the bugs and reported it with an effective approach of a real-life attack scenario. Let’s Start First we will…

Bug Bounty

4 min read

Chaining Bugs to get my First Bug Bounty
Chaining Bugs to get my First Bug Bounty
Bug Bounty

4 min read


Published in

InfoSec Write-ups

·Dec 5, 2022

OTP Leaking Through Cookie Leads to Account Takeover

OTP Bypass — Hello Hackers, This time I am going to discuss an OTP leaking vulnerability that leads to account takeover in an e-commerce website. Let’s Start What is OTP? A one-time password, also known as a one-time PIN, one-time authorization code or dynamic password, is a password that is valid for only one…

Bug Bounty

3 min read

OTP Leaking Through Cookie Leads to Account Takeover
OTP Leaking Through Cookie Leads to Account Takeover
Bug Bounty

3 min read


Nov 19, 2022

TryHackMe-Neighbour

Room link :: https://tryhackme.com/room/neighbour Overview Easy-rated machine dealing with IDOR, created by cmnatic. This is a very very easy machine that can be solved within minutes. What is IDOR? An Insecure direct object reference is a type of access control vulnerability in digital security. This can occur when a web application…

Tryhackme

3 min read

TryHackMe-Neighbour
TryHackMe-Neighbour
Tryhackme

3 min read


Published in

InfoSec Write-ups

·Nov 17, 2022

Reflected XSS using Double Encoding

Bypassing XSS filters using Double Encoding — Hello Hackers, Recently I started my bug hunting journey and got an XSS by Bypassing Cloudflare WAF (you can read about it here). Now I am back with another XSS by Double Encoding. This attack technique consists of encoding user request parameters twice in hexadecimal format to bypass security controls…

Xss Filter Bypass

3 min read

Reflected XSS using Double Encoding
Reflected XSS using Double Encoding
Xss Filter Bypass

3 min read


Nov 10, 2022

FETCH THE FLAG CTF 2022

HOSTED BY SNYK Hello everyone, i hope you all are doing well. This is my first writeup, feel free to comment your suggestions which helps me to improve. In this writeup I am solving some challenges from the recent FETCH THE FLAG CTF by SNYK. Going directly in to it… …

Ctf

4 min read

FETCH THE FLAG CTF 2022
FETCH THE FLAG CTF 2022
Ctf

4 min read

ag3n7

ag3n7

230 Followers

Cyber Security Researcher https://twitter.com/ag3n7apk

Following
  • Mohamed Anani

    Mohamed Anani

  • Cristi Vlad

    Cristi Vlad

  • InfoSec Write-ups

    InfoSec Write-ups

  • Harikrishnan P

    Harikrishnan P

  • Pawan Chhabria

    Pawan Chhabria

See all (57)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech

Teams