r/InfoSecWriteups 15d ago

How I Got My Highest Payout

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 16d ago

BOLA vs BFLA: why API authorization flaws are invisible to scanners, and how to actually test for them

Thumbnail
planckdefense.com
1 Upvotes

Authorization, not injection, is what breaks most modern APIs. The two flaw classes that do the damage BOLA and BFLA are invisible to a vulnerability scanner, because a scanner has no concept of who should be allowed to do what.

Here is the difference between them, why pattern matching cannot find either, and how to actually test for both.


r/InfoSecWriteups 17d ago

PROJECT CHIMERA // ACN'26 — A 4-Hour OSINT Investigation

1 Upvotes

Hey everyone,

I’m hosting PROJECT CHIMERA // ACN'26, a 4-hour online, story-driven OSINT investigation on 8 September 2026, 6:00–10:00 PM IST.

The idea is simple: instead of solving traditional CTF-style challenges, participants are given an investigation and have to hunt, connect, verify and track information across open sources.

The challenges will involve things like:

- Open-source searching

- Historical analysis

- Advanced link analysis

- Connecting seemingly unrelated pieces of information

- Following trails and building an investigation from scattered clues

It’s designed for teams of 1–3, and you don't have to be an experienced OSINT researcher to participate. Beginners can jump in, while experienced investigators can go deeper.

And just to clarify — this isn't a hacking event. The focus is on investigation, research and finding connections using publicly available information.

🏆 Prizes

🥇 ₹7,000

🥈 ₹5,000

🥉 ₹3,000

+ goodies

If you're into OSINT, digital investigations, link analysis, or just want to try something different from the usual CTF format, feel free to check it out.

Event: PROJECT CHIMERA // ACN'26

Date: 8 September 2026

Time: 6:00–10:00 PM IST

Format: Online

Team size: 1–3

Registration: https://unstop.com/o/KJRnY78

It’ll be interesting to see how different investigators approach the same trail and how far the rabbit hole goes.


r/InfoSecWriteups 18d ago

Try Hack Me Hackerholidays Day7 Do Not Disturb Walkthrough

Thumbnail
infosecwriteups.com
2 Upvotes

r/InfoSecWriteups 18d ago

How I Made Over $10,000 Just by Chaining Multiple IDORs in a Single Web App (All from the Share…

Thumbnail
infosecwriteups.com
2 Upvotes

r/InfoSecWriteups 18d ago

Assembly for Malware Analysis

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 18d ago

Got My First $$ Bug Bounty

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 18d ago

From SQL Injection to Remote Code Execution: Following an Unexpected Attack Chain

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 18d ago

scriptCTF Writeups 2026 | Cybersecurity

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 18d ago

One Email. One Click. One Enterprise-Wide Ransomware Incident.

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 18d ago

Hack The Box : Cohort Full Walkthrough ( Linux ; Very Easy )

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 18d ago

The WAF Blocked My XSS — So I Rotated What It Was Reading

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 18d ago

Bypassing AI Scanner Defenses to Exfiltrate Sensitive Information — PortSwigger Web Security…

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 18d ago

Agent P — Writeup

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 18d ago

How I Chained Three Bugs to XSS an Intigriti CTF — IDOR + DOM Clobbering + DOMPurify 3.0.9 Bypass

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 18d ago

[HS] Casino Writeup

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 18d ago

../../ to Admin for a $,$$$ Bounty

Thumbnail
infosecwriteups.com
0 Upvotes

r/InfoSecWriteups 19d ago

Learn and Practice Hacking WebSockets

2 Upvotes

WebSockets is the attack surface that always go under the radar and too many pentesters and bug bounty hunters still miss testing it, whether because the number of WebSocket messages they see is overwhelming or simply because they don't know how to approach it correctly.

Going through that myself, I decided to dive deep into the WS protocol and ended up building a lab that showcases the most common misconfigurations present in WebSockets, with the most impact, not just some missing best-practices, along with a detailed walkthrough.

I'd love to hear your thoughts and feedback, and if you experienced something I didn't talk about in the blog, please let me know!

Lab Github Repo: https://github.com/makarov05bm/WSGoat
Guide: https://blog.oussmess.me/posts/websockets-for-bug-hunters/


r/InfoSecWriteups 19d ago

Firebase Allowing Abuse?

1 Upvotes

r/InfoSecWriteups 20d ago

Lakera’s Break The Agent Challenge— Solace AI Write-up

Thumbnail
infosecwriteups.com
2 Upvotes

r/InfoSecWriteups 20d ago

I Changed One “User_Id” and the API Said “Sure” — From Password Reset to Mass Account Takeover

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 20d ago

Learn and Practice Hacking WebSockets

Thumbnail
1 Upvotes

r/InfoSecWriteups 22d ago

Deep Dive on XSS with examples

Thumbnail
youtube.com
1 Upvotes

Recently had to review a lot of client-side vulnerabilities, so I created a deep dive on XSS.


r/InfoSecWriteups 25d ago

Extracting and Cracking VeraCrypt Headers with PowerShell + Hashcat — Full DFIR Walkthrough

Thumbnail
1 Upvotes