Open in app

Sign In

Write

Sign In

Aidil Arief
Aidil Arief

455 Followers

Home

About

Nov 30, 2022

Stored XSS at https://www.tiktok.com/ the name of the attacker’s account carrying XSS payload will be triggered when the victim Send Video

Hi everyone, When I decided to do some Bug Hunting on the TikTok program, and I got some XSS Stored in a few months. After waiting for so long to disclose these findings, and finally, this article is disclosed. Follow Me :)

Xss Vulnerability

3 min read

Stored XSS at https://www.tiktok.com/
Stored XSS at https://www.tiktok.com/
Xss Vulnerability

3 min read


Aug 25, 2022

SOLUTION to XSS Challenge From V1 — V8

Hi everyone, Bagaimana kabar anda? Saya harap kita semua baik-baik saja. Saya ingin membagikan sebuah artikel terkait solusi untuk ChallengeXSS dari Revan AR ( https://tools.revanar.dev/lab/ ) Sebelum memulainya, saya sudah terlebih dahulu meminta izin ke pemilik Challange untuk publish ini, dan akhirnya disetujui. Ikuti Saya :) XSS Challenge V1 Di…

Xss Vulnerability

5 min read

SOLUTION to XSS Challenge From V1 — V8
SOLUTION to XSS Challenge From V1 — V8
Xss Vulnerability

5 min read


Jul 28, 2022

XSS in Open Redirect which uses attribute rel=”noopener follow” target=”_blank Via Browser Modern

Hi everyone This time I will write a little XSS solution in Open Redirect that uses the attribute rel=”noopener follow” target=”_blank. Here’s the code snippet: <a class=”test” title=”test” href=”javascript:alert()” rel=”noopener follow” target=”_blank”>CLICK</a> Source : Page Title Edit descriptiontest.secrash.com From the code snippet above, I tried to open it through several Modern Browsers: Google Chrome

Xss Bypass

2 min read

XSS in Open Redirect which uses attribute rel=”noopener follow” target=”_blank Via Browser Modern
XSS in Open Redirect which uses attribute rel=”noopener follow” target=”_blank Via Browser Modern
Xss Bypass

2 min read


Jun 29, 2022

XSS Blind Stored at 2 Assets TikTok

Hi everyone, In this article, I share the findings of XSS Blind Stored at 2 TikTok Assets. When I decided to hunt for bugs in the TikTok program, and I spent 1 month looking for this XSS. This XSS finding started when I created a product on a TikTok seller…

Xss Bypass

3 min read

XSS Blind Stored at 2 Assets TikTok
XSS Blind Stored at 2 Assets TikTok
Xss Bypass

3 min read


Jun 16, 2022

XSS Blind Stored at Asset Domain Android Apps TikTok

Hi everyone First, let me introduce a little background, I am a young teenager graduated from Senior High School and IT Security Enthusiast from Indonesia. Now, I am 21 years old. I once had a dream that I wanted to find a valid vulnerability on some Tech Giant Site, and…

Xss Attack

3 min read

XSS Blind Stored at Asset Domain Android Apps TikTok
XSS Blind Stored at Asset Domain Android Apps TikTok
Xss Attack

3 min read


May 28, 2022

The first XSS STORED find in YANDEX Bug Bounty Program

Assalamualaikum Bug Hunter & Hi Everyone. This time I want to share a finding of the XSS STORED Vulnerability on Yandex. Previously I have tried to search for vulnerabilities in the Yandex Bug Bounty Program, and as a result I did not find any vulnerabilities in Yandex. …

Xss Vulnerability

4 min read

The first XSS STORED find in YANDEX Bug Bounty Program
The first XSS STORED find in YANDEX Bug Bounty Program
Xss Vulnerability

4 min read


Mar 8, 2022

($$$) IDOR via GET Request which can SOLD all User Products

Hi everyone, In this article I want to share my findings on a Private Program at Hackerone which is very unique. Let’s take a minute to take a look at this :) When I was hunting on a private program on Hackerone, I came across a scope of https://redacted.com/. …

Bug Bounty

2 min read

($$$) IDOR via GET Request which can SOLD all User Products
($$$) IDOR via GET Request which can SOLD all User Products
Bug Bounty

2 min read


Jan 25, 2022

First Valid BUG Finding At Microsoft And I Got the Acknowledgments Page Microsoft

Hi Everyone. This time I would like to share an article about the findings of the XSS STORED Vulnerability in one of Microsoft Forum subdomains, namely https://powerusers.microsoft.com/ . This is my first vulnerability finding in the Microsoft Security Response Center Program (MSRC). …

Xss Attack

3 min read

First Valid BUG Finding At Microsoft And I Got the Acknowledgments Page Microsoft
First Valid BUG Finding At Microsoft And I Got the Acknowledgments Page Microsoft
Xss Attack

3 min read


Jan 11, 2022

[ CVE-2021-46146 ] Stored XSS via WikibaseMediaInfo caption fields at commons.wikimedia.org

Hi everyone, On Oct 16 2021, we discovered this XSS STORED vulnerability at https://commons.wikimedia.org/ and at that time we immediately reported it to Team WikiMedia. Let’s take a minute to look at this. At that time, we found a subdomain https://commons.wikimedia.org/ , and there was a File upload feature.

Xss Vulnerability

3 min read

[ CVE-2021-46146 ] Stored XSS via WikibaseMediaInfo caption fields at commons.wikimedia.org
[ CVE-2021-46146 ] Stored XSS via WikibaseMediaInfo caption fields at commons.wikimedia.org
Xss Vulnerability

3 min read


Dec 22, 2021

[CVE-2021–44855] Blind Stored XSS in VisualEditor media dialog at Wikipedia

Assalamualaikum Bug Hunter & Hi Everyone This time we want to write an article about “CVE-2021–44855 Blind Stored XSS in VisualEditor media dialog” which we found on Wikipedia. On October 16, 2021, we discovered the XSS STORED vulnerability issue at https://commons.wikimedia.org/ (https://phabricator.wikimedia.org/T293556CVE-2021-44855) …

Wikimedia

2 min read

[CVE-2021–44855] Blind Stored XSS in VisualEditor media dialog at Wikipedia
[CVE-2021–44855] Blind Stored XSS in VisualEditor media dialog at Wikipedia
Wikimedia

2 min read

Aidil Arief

Aidil Arief

455 Followers

Keep to secure the internet

Following
  • Quizizz

    Quizizz

  • Suraj M Durgad

    Suraj M Durgad

  • Ash-Shiddiqul Akbar Hidayat

    Ash-Shiddiqul Akbar Hidayat

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech