exploitedbuffer's profile picture. ‼️ Bug Bounty
‼️ Learning .NET
‼️ Studying Cyber Security
‼️ LucidHub Developer
‼️ Encryption Enthusiasts
‼️ Computer Science
‼️ Com since 2015

☞ Null

@exploitedbuffer

‼️ Bug Bounty ‼️ Learning .NET ‼️ Studying Cyber Security ‼️ LucidHub Developer ‼️ Encryption Enthusiasts ‼️ Computer Science ‼️ Com since 2015

SQL Vulnerability found in a website what's written in PHP. I've got access to their accounts usernames and passwords. Which the site owner is breaking the Data Protection Act, because they're not even hashing the passwords....

exploitedbuffer's tweet image. SQL Vulnerability found in a website what's written in PHP.
I've got access to their accounts usernames and passwords. Which the site owner is breaking the Data Protection Act, because they're not even hashing the passwords....

It's really getting ridiculous, the majority of small websites have silly vulnerabilities, this site had default logins for there Administrator account. This taken me less than 10 minuets to have obtained access to all of the accounts and there logs ie Payments, Logs and more...

exploitedbuffer's tweet image. It's really getting ridiculous, the majority of small websites have silly vulnerabilities, this site had default logins for there Administrator account.
This taken me less than 10 minuets to have obtained access to all of the accounts and there logs ie Payments, Logs and more...

I'll be back to finding vulnerabilities in a few. May be gone for awhile ;)


Remember to always secure your account. that can be using a secure password and or two factor Authentication.


Another XSS Reflected Vulnerability, lulz.

exploitedbuffer's tweet image. Another XSS Reflected Vulnerability, lulz.

☞ Null reposted

@PatchMyBypass Thank you, please describe the issue in DM.


So I was messing around on Google Translate, and I never thought this would work, you would think that a multi BILLION dollar company would have all XSS vulnerabilities patched. lulz BUT I heard that these vulnerabilities are common for google, therefore may not be a 0day!!

exploitedbuffer's tweet image. So I was messing around on Google Translate, and I never thought this would work, you would think that a multi BILLION dollar company would have all XSS vulnerabilities patched. lulz

BUT I heard that these vulnerabilities are common for google, therefore may not be a 0day!!

United States Trends

Loading...

Something went wrong.


Something went wrong.