intruder

2 articles
sort: new top best
clear filter
0 8/10

Detailed walkthrough of exploiting blind SQL injection in Oculus' developer portal by bypassing multiple filters (no whitespace, no commas) using comment syntax and MySQL alternative function syntax, ultimately extracting admin session tokens and gaining administrative access.

Oculus Facebook Josip Franjković Jon (Bitquark) developer.oculusvr.com CompanyAction.php PHPSESSID MySQL
josipfranjkovic.blogspot.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details
0 6/10

A researcher discovered a race condition vulnerability in a bug bounty program that allowed bypassing authorization controls to create more team members than allowed by using Burp Suite's Intruder tool to send simultaneous requests.

Pravinrp Burp Suite Veracode
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details