bug-bounty488
google318
xss283
microsoft259
facebook226
rce175
apple153
exploit147
malware112
account-takeover109
bragging-post102
cve92
csrf85
privilege-escalation81
authentication-bypass66
stored-xss65
writeup63
phishing60
dos57
browser57
reflected-xss57
ssrf52
react51
access-control51
input-validation49
cross-site-scripting48
supply-chain48
aws47
cloudflare47
node46
smart-contract45
sql-injection45
ethereum44
docker44
defi43
web-application43
web-security43
reverse-engineering42
oauth42
web340
lfi37
burp-suite36
idor36
vulnerability-disclosure35
race-condition33
html-injection33
smart-contract-vulnerability32
csp-bypass32
clickjacking31
information-disclosure31
0
2/10
bug-bounty
A bug bounty hunter discovered admin panel access through SQL injection by enumerating historical URLs with waybackurls/gau, filtering for SQL injection patterns with gf, testing with a private tool, extracting admin credentials from the database, and finding the login panel URL in website source code.
sql-injection
admin-panel-access
bug-bounty
recon
url-enumeration
credential-extraction
bragging-post
waybackurls
gau
gf
httpx
Ratnadip Gajbhiye