Author Archive

IDOR (at Private Bug Bounty Program) that could Leads to Personal Data Leaks

Author: | Categories: Bug Report, Web Apps, Write-Up No comments
  In the name of Allah, the Most Gracious, the Most Merciful. Please kindly visit this simple paper directly to looking this release in simple: [English Version] IDOR (at Private Bug Bounty Program) that could Leads to Personal Data Leaks I. PRE-INTRODUCTION Few months ago, I got an invitation

Ribose – IDOR with Simple CSRF Bypass – Unrestricted Changes and Deletion to other Photo Profile

Author: | Categories: Bug Report, Web Apps, Write-Up No comments
In the name of Allah, the Most Gracious, the Most Merciful. Please kindly visit this simple paper directly to looking this release in simple: [English Version] Ribose – IDOR with Simple CSRF Bypass – Unrestricted Deletion to other Photo Profile I. ABSTRACT Introducing ourselves in the use of social

[Bahasa] Multiple Parameter Pollution Bugs at “Battle Camp” Game that could Leads to Several Illegal Action

Author: | Categories: Mobile Apps, Write-Up in Bahasa No comments
In the name of Allah, the Most Gracious, the Most Merciful. Silahkan langsung mengunduh paper sederhana pada tautan berikut ini untuk dapat melihat tulisan ini lebih nyaman: [Bahasa] Multiple Parameter Pollution Bug at “Battle Camp” Game that could Leads to Several Illegal Actions I. SELINGAN INSTAN YANG TIDAK TERLALU

Lack of Binary Protection at Asus “Vivo Baby” and “HiVivo” for Android that could Result of Several Security Issues (CVE-2017-17944 & CVE-2017-17945)

Author: | Categories: Bug Report, Mobile Apps, Write-Up No comments
In the name of Allah, the Most Gracious, the Most Merciful. Please kindly visit this simple paper directly to looking this release (for a simple look): [English Version] Asus – Lack of Binary Protection at Asus “Vivo Baby” and “HiVivo” for Android that could Result of Several Security Issues

Bypassing the Current Password Protection at PayPal Tech-Support

Author: | Categories: Bug Report, Web Apps, Write-Up No comments
In the name of Allah, the Most Gracious, the Most Merciful. Please kindly visit this simple paper directly to looking this release: [English Version] PayPal – Bypassing the Current Password Protection at PayPal Tech-Support For completing the explanation, we upload the unlisted video at Youtube: https://youtu.be/QGBpjDDs9pY

Information Disclosure at PayPal and Xoom (PayPal Acquisition) via Search Engine

Author: | Categories: Bug Report, Web Apps, Write-Up No comments
In the name of Allah, the Most Gracious, the Most Merciful. Please kindly visit this simple paper directly to looking this release: [English Version] PayPal – Information Disclosure at PayPal and Xoom (PayPal Acquisition) via Search Engine For completing the explanation, we upload the unlisted video at Youtube for

Turning Self-XSS into non-Self Stored-XSS via Authorization Issue at “PayPal Tech-Support and Brand Central Portal”

Author: | Categories: Bug Report, Web Apps, Write-Up No comments
Please kindly visit this simple paper directly to looking this release (for a simple look): [English Version] PayPal – Turning Self-XSS into non-Self Stored-XSS via Authorization Issue For completing the explanation, we upload the unlisted video at Youtube for both of scenario: Stored XSS (via Malicious SVG File) at

FortiNet – Unrestricted Deletion to All Other Sub Account via IDOR at Support Portal

Author: | Categories: Bug Report, Web Apps, Write-Up No comments
I. ABSTRACT As a part for completing the support to all the customer, FortiNet providing the support portal (located at: https://support.fortinet.com/Home.aspx) for their customer to communicate each other. One of the interesting feature that available at the Support Portal is “manage user” that could be used to connected with

BigTree CMS – Multiple Security Issue of CSRF at Few Parameters (CVE-2017-6914 … 6918)

Author: | Categories: Bug Report, Web Apps, Write-Up No comments
I. ABSTRACT As quoted from the official site of BigTree CMS, BigTree CMS is an open source content management system built on PHP and MySQL. It was created by – and for – user experience and content strategy experts. BigTree’s user system is designed for a single webmaster or

[Bahasa] Tokopedia – Unrestricted Deletion to All of People’s Bank Account

Author: | Categories: Write-Up in Bahasa No comments
I. ABSTRACT Kemudahan dalam melakukan penerimaan pembayaran dari hasil penjualan secara online tentu menjadi impian bagi para penjual. Demi mewujudkan kemudahan ini, Tokopedia pun mengeluarkan salah satu fitur berupa “Tambah Rekening Bank” yang dapat digunakan untuk menerima hasil pembayaran setelah seluruh proses transaksi kepada pembeli dilakukan (dalam hal ini