Open in app

Sign in

Write

Sign in

Devansh chauhan
Devansh chauhan

12 Followers

Home

About

Pinned

Story of Http password reset link for $$$

In the digital age, online security is paramount, and one crucial aspect of this is the protection of user credentials. Password reset functionality is a common feature on many websites, allowing users to regain access to their accounts in the event of a forgotten password. …

Bugbounty

3 min read

Story of Http password reset link for $$$
Story of Http password reset link for $$$
Bugbounty

3 min read


Pinned

Hijacking Broken Links for $$$

What is Broken Link Hijacking? Broken link hijacking (BLH) is a type of web attack. It exploits external links that are no longer valid. If your website or web application uses resources loaded from external URLs or points to such resources and these resources are no longer there , attackers…

Bug Bounty

2 min read

Hijacking Broken Links for $$$
Hijacking Broken Links for $$$
Bug Bounty

2 min read


Pinned

Securing the University by failure of invalidating of session

Tale of securing the university of united states. I was seeing my linkedin and seen the post of the Letter of appreciation by the Drexel University and got the feeling of getting one but ended but up getting more then one and a hall of fame too. Vulnerability Name: Old…

Bug Bounty

2 min read

Securing the University by failure of invalidating of session
Securing the University by failure of invalidating of session
Bug Bounty

2 min read


Pinned

Story Of Pre-Account Takeover via 0auth Misconfiguration

Hello guys, Today I am going to share one of my interesting findings on the private program . Since this is on a private program so I will be using it as target.com . Let’s get started. I picked one of the subdomain a.target.com and there is a registration page…

Vulnerability

2 min read

Story Of Pre-Account Takeover via 0auth Misconfiguration
Story Of Pre-Account Takeover via 0auth Misconfiguration
Vulnerability

2 min read


Pinned

Story of securing Mercedes FROM CRLF

As a bug bounty hunter, I’m always on the lookout for security vulnerabilities that I can report to companies and earn rewards. Recently, I discovered a CRLF injection vulnerability on Mercedes , and in this post, I’m going to share how I found it and the impact it had. First, let me explain what CRLF injection is. CRLF stands for “Carriage Return Line Feed”, which are special characters used to represent the end of a line in various protocols, including HTTP. …

Bug Bounty Writeup

2 min read

Story of securing Mercedes FROM CRLF
Story of securing Mercedes FROM CRLF
Bug Bounty Writeup

2 min read

Devansh chauhan

Devansh chauhan

12 Followers

Bug Bouty hunter || CCIO

Help

Status

About

Careers

Blog

Privacy

Terms

Text to speech

Teams