Skip to content
appsecwriteups.com

Learning AppSec Through Android & Web Vulnerability Writeups

  • Home
  • Android
  • Web
  • Desktop
  • Shielded
  • Home
  • Android
  • Web
  • Desktop
  • Shielded
Top Writeup
Home » Archives for May 2025
How I Discovered a Google Cloud Storage Bucket Misconfiguration on an Adult Site and Earned a $250 Bounty
Posted inWeb

How I Discovered a Google Cloud Storage Bucket Misconfiguration on an Adult Site and Earned a $250 Bounty

Posted by By Jivan Magare May 26, 2025
Hello friends, I’m Jivan, and I’m back with another write-up about a Google Cloud Storage…
Read More
How I Discovered a Critical Vulnerability via Hardcoded GCP Credentials in an Android App and Earned $700 Bounty on Cyberbay
Posted inAndroid

How I Discovered a Critical Vulnerability via Hardcoded GCP Credentials in an Android App and Earned $700 Bounty on Cyberbay

Posted by By Jivan Magare May 17, 2025
Hello aspiring bug bounty hunters! I’m Jivan, and I’m back with another security vulnerability that…
Read More
How I Discovered an HTML Injection Vulnerability in the Origin Query Parameter of a Password Reset Email and Earned a $75 Bounty
Posted inWeb

How I Discovered an HTML Injection Vulnerability in the Origin Query Parameter of a Password Reset Email and Earned a $75 Bounty

Posted by By Jivan Magare May 11, 2025
Hello guys, I’m Jivan, and I’m back with a new write-up where I discovered an…
Read More
How I Found a No Rate Limit Vulnerability on a Login Endpoint, Earned a 100€ Bounty, and My Approach to Testing for No Rate Limit Issues
Posted inWeb

How I Found a No Rate Limit Vulnerability on a Login Endpoint, Earned a 100€ Bounty, and My Approach to Testing for No Rate Limit Issues

Posted by By Jivan Magare May 10, 2025
Hi friends, I’m Jivan, back with another write-up related to a No Rate Limit vulnerability.In…
Read More
How I Discovered a High-Severity IDOR Vulnerability in an Android Hotel Booking App and Earned a $80 Bounty
Posted inAndroid

How I Discovered a High-Severity IDOR Vulnerability in an Android Hotel Booking App and Earned a $80 Bounty

Posted by By Jivan Magare May 9, 2025
Hi everyone, Jivan here!I'm back with another Android vulnerability report. In this write-up, I’ll walk…
Read More
How I Found an OTP Bypass Vulnerability in an Android App and Was Rewarded 150€ Euros as a Bounty
Posted inAndroid

How I Found an OTP Bypass Vulnerability in an Android App and Was Rewarded 150€ Euros as a Bounty

Posted by By Jivan Magare May 9, 2025
Welcome to my very first bug bounty write-up! Hi, I'm Jivan — a passionate self-taught…
Read More

Archives

  • October 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Comments

  1. Jivan Magare on How I Found a No Rate Limit Vulnerability on a Login Endpoint, Earned a 100€ Bounty, and My Approach to Testing for No Rate Limit Issues
  2. Shubham on How I Found a No Rate Limit Vulnerability on a Login Endpoint, Earned a 100€ Bounty, and My Approach to Testing for No Rate Limit Issues
  3. Jivan Magare on CSRF Account Deletion: How I Turned an “Excluded” Bug Into $87 USD Bounty
  4. anonymous on CSRF Account Deletion: How I Turned an “Excluded” Bug Into $87 USD Bounty
  5. Jivan Magare on How I Found a No Rate Limit Vulnerability on a Login Endpoint, Earned a 100€ Bounty, and My Approach to Testing for No Rate Limit Issues

Recent Posts

  • Protected: My First Day Pentesting Thick‑Client Apps — Discovered a Critical IDOR in a Desktop Client with a Full Black‑Box Approach
  • How I Found a Critical Privilege Escalation That Let an Unprivileged User Become Admin and Earn $579 USD Bounty
  • CSRF Account Deletion: How I Turned an “Excluded” Bug Into $87 USD Bounty
  • How to Identify and Handle Firebase Security Misconfigurations A Case Study
  • Security Testing via Black-Box Approach: Two Important Android App Issues Discovered Across the Same Company

Categories

  • Android
  • Desktop
  • Web

🔗Follow Me

  • LinkedIn

💬Contact Us

📩 Have questions, suggestions, or found a security issue? Reach out to us at: contact@appsecwriteups.com

🛡️Privacy Policy

Privacy Policy

Copyright 2025 — appsecwriteups.com. All rights reserved. appsecwriteups.com
Scroll to Top