Open in app

Sign in

Write

Sign in

Japz Divino
Japz Divino

1.2K followers

Home

About

Pinned
InfoSec Write-ups

Published in

InfoSec Write-ups

Bypass HackerOne 2FA requirement and reporter blacklist

Severity: Medium (5.0) — High (7.1) Weakness: Improper Authorization Bounty: $10,000   Summary:

Oct 31, 2018
6
Bypass HackerOne 2FA requirement and reporter blacklist
Bypass HackerOne 2FA requirement and reporter blacklist
Oct 31, 2018
6
Pinoy White Hat

Published in

Pinoy White Hat

Easy $10,000 bounty using Wayback Machine

Severity: Critical (9 ~ 10)  Weakness: Sensitive Information Disclosure Bounty: $10,000

Jan 23
7
Easy $10,000 bounty using Wayback Machine
Easy $10,000 bounty using Wayback Machine
Jan 23
7
Pinoy White Hat

Published in

Pinoy White Hat

Alleged 45 Million NBI Philippines Data Leak Raises Privacy Concerns

An alleged data leak concerning the Philippine National Bureau of Investigation (NBI) has been making waves online after being posted on…

Jan 20
1
Alleged 45 Million NBI Philippines Data Leak Raises Privacy Concerns
Alleged 45 Million NBI Philippines Data Leak Raises Privacy Concerns
Jan 20
1
Pinoy White Hat

Published in

Pinoy White Hat

IDOR on HackerOne Embedded Submission Form

Severity: Low (3.7) — Medium (4.4) Weakness: Improper Access Control Bounty: $2,500

Dec 17, 2024
11
IDOR on HackerOne Embedded Submission Form
IDOR on HackerOne Embedded Submission Form
Dec 17, 2024
11
Pinoy White Hat

Published in

Pinoy White Hat

Redacted usernames disclosure in "Export as .pdf" feature

Severity: Low (3.4) Weakness: Sensitive Information Disclosure Bounty: $500

Aug 7, 2023
Redacted usernames disclosure in "Export as .pdf" feature
Redacted usernames disclosure in "Export as .pdf" feature
Aug 7, 2023
Pinoy White Hat

Published in

Pinoy White Hat

Getting email address of any HackerOne user worth $12,500

Severity: High (7.5) Weakness: Sensitive Information Disclosure Bounty: Duplicate (First researcher receives $12,500)

Jul 4, 2023
1
Getting email address of any HackerOne user worth $12,500
Getting email address of any HackerOne user worth $12,500
Jul 4, 2023
1
Pinoy White Hat

Published in

Pinoy White Hat

Harvesting all private invites using leave program fast-tracked invitation and security@ email…

Severity: Medium (6.1) Weakness: Business Logic Errors (CWE-840)

Oct 22, 2018
2
Harvesting all private invites using leave program fast-tracked invitation and security@ email…
Harvesting all private invites using leave program fast-tracked invitation and security@ email…
Oct 22, 2018
2
InfoSec Write-ups

Published in

InfoSec Write-ups

SOP Bypass using rel=”noreferrer”

Note before reading:

Oct 17, 2018
1
SOP Bypass using rel=”noreferrer”
SOP Bypass using rel=”noreferrer”
Oct 17, 2018
1
Pinoy White Hat

Published in

Pinoy White Hat

Security teams Internal attachments can be exported via “Export as .zip” feature on HackerOne

Hello Internet, this blog is about my findings on hackerone own bug bounty program late 2016, a simple information disclosure which…

Oct 17, 2018
Oct 17, 2018
Pinoy White Hat

Published in

Pinoy White Hat

IDOR on HackerOne Hacker Review “What Program Say”

Severity: Low

Sep 2, 2017
IDOR on HackerOne Hacker Review “What Program Say”
IDOR on HackerOne Hacker Review “What Program Say”
Sep 2, 2017
Japz Divino

Japz Divino

1.2K followers

OSCP | CCBH | Bug Bounty Hunter

Following
  • @ro0taddict

    @ro0taddict

  • Pinoy White Hat

    Pinoy White Hat

  • coffinxp

    coffinxp

  • ar33zy

    ar33zy

  • Immunefi

    Immunefi

See all (142)

Help

Status

About

Careers

Press

Blog

Privacy

Rules

Terms

Text to speech