bug-bounty498
google349
xss301
microsoft292
facebook262
rce211
exploit199
malware169
apple161
cve136
account-takeover115
bragging-post102
privilege-escalation95
csrf90
phishing86
browser75
writeup74
authentication-bypass69
supply-chain67
dos66
stored-xss65
reflected-xss57
ssrf56
reverse-engineering55
react52
access-control52
input-validation49
cross-site-scripting48
cloudflare47
aws47
web-security46
lfi46
docker46
sql-injection45
smart-contract45
ethereum44
web-application44
ctf43
oauth43
defi43
web343
node42
pentest39
open-source39
race-condition39
cloud37
idor37
info-disclosure36
burp-suite36
auth-bypass35
0
7/10
Security researcher discovered an SSRF vulnerability in Yahoo! Guesthouse by finding a SAML endpoint through recon, then exploiting the BouncerSAMLRemoteSessionHost cookie which accepted arbitrary hostname values, causing the backend to make requests to attacker-controlled servers.
ssrf
saml
recon
cookie-injection
burp-suite
xxe
dns-exfiltration
subdomain-enumeration
bug-bounty
yahoo
Yahoo! Guesthouse
Th3G3nt3lman
BouncerSAMLRemoteSessionHost
https://gh.bouncer.login.yahoo.com/
https://alpha.keyserver.yahoo.com/saml
dip2.gq1.yahoo.com