Open in app

Sign in

Write

Sign in

Aidil Arief
Aidil Arief

619 Followers

Home

About

May 2

How do I Bypass Payment when a Subscription ends so I don’t have to pay for my subscription

Hi Everyone, When I do Bug Hunting. I spend a lot of time looking at the API flow in processing requests. In this article, I found a unique problem where a user with an Admin role can remove user access with an Owner role ( highest role access rights ). …

Bypass

4 min read

How do I Bypass Payment when a Subscription ends so I don’t have to pay for my subscription
How do I Bypass Payment when a Subscription ends so I don’t have to pay for my subscription
Bypass

4 min read


Mar 4

[ CVE-2023–26046 & CVE-2023–26047 ] XSS Bypass WAF at teler-waf

Hi Everyone, teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks and improve the security of Go-based web applications. teler-waf is a comprehensive security solution for Go-based web applications. It acts as an HTTP middleware, providing an easy-to-use interface for integrating IDS functionality…

Xss Bypass

5 min read

[ CVE-2023–26046 & CVE-2023–26047 ] XSS Bypass WAF at teler-waf
[ CVE-2023–26046 & CVE-2023–26047 ] XSS Bypass WAF at teler-waf
Xss Bypass

5 min read


Feb 20

Bypassing SSO Authentication from the Login Without Password Feature Lead to Account Takeover

Hi Everyone, When I did Bug Hunting, I found the Login without Password feature. The Login without Password feature is a feature that is used for valid account users to log in without a password or valid account users can only log in using the OTP ( One-Time Password )…

Bug Bounty

3 min read

Bypassing SSO Authentication from the Login Without Password Feature Lead to Account Takeover
Bypassing SSO Authentication from the Login Without Password Feature Lead to Account Takeover
Bug Bounty

3 min read


Nov 30, 2022

Stored XSS at https://www.tiktok.com/ the name of the attacker’s account carrying XSS payload will be triggered when the victim Send Video

Hi everyone, When I decided to do some Bug Hunting on the TikTok program, and I got some XSS Stored in a few months. After waiting for so long to disclose these findings, and finally, this article is disclosed. Follow Me :)

Xss Vulnerability

3 min read

Stored XSS at https://www.tiktok.com/
Stored XSS at https://www.tiktok.com/
Xss Vulnerability

3 min read


Aug 25, 2022

SOLUTION to XSS Challenge From V1 — V8

Hi everyone, Bagaimana kabar anda? Saya harap kita semua baik-baik saja. Saya ingin membagikan sebuah artikel terkait solusi untuk ChallengeXSS dari Revan AR ( https://tools.revanar.dev/lab/ ) Sebelum memulainya, saya sudah terlebih dahulu meminta izin ke pemilik Challange untuk publish ini, dan akhirnya disetujui. Ikuti Saya :) XSS Challenge V1 Di…

Xss Vulnerability

5 min read

SOLUTION to XSS Challenge From V1 — V8
SOLUTION to XSS Challenge From V1 — V8
Xss Vulnerability

5 min read


Jul 28, 2022

XSS in Open Redirect which uses attribute rel=”noopener follow” target=”_blank Via Browser Modern

Hi everyone This time I will write a little XSS solution in Open Redirect that uses the attribute rel=”noopener follow” target=”_blank. Here’s the code snippet: <a class=”test” title=”test” href=”javascript:alert()” rel=”noopener follow” target=”_blank”>CLICK</a> Source : Page Title Edit descriptiontest.secrash.com From the code snippet above, I tried to open it through several Modern Browsers: Google Chrome

Xss Bypass

2 min read

XSS in Open Redirect which uses attribute rel=”noopener follow” target=”_blank Via Browser Modern
XSS in Open Redirect which uses attribute rel=”noopener follow” target=”_blank Via Browser Modern
Xss Bypass

2 min read


Jun 29, 2022

XSS Blind Stored at 2 Assets TikTok

Hi everyone, In this article, I share the findings of XSS Blind Stored at 2 TikTok Assets. When I decided to hunt for bugs in the TikTok program, and I spent 1 month looking for this XSS. This XSS finding started when I created a product on a TikTok seller…

Xss Bypass

3 min read

XSS Blind Stored at 2 Assets TikTok
XSS Blind Stored at 2 Assets TikTok
Xss Bypass

3 min read


Jun 16, 2022

XSS Blind Stored at Asset Domain Android Apps TikTok

Hi everyone First, let me introduce a little background, I am a young teenager graduated from Senior High School and IT Security Enthusiast from Indonesia. Now, I am 21 years old. I once had a dream that I wanted to find a valid vulnerability on some Tech Giant Site, and…

Xss Attack

3 min read

XSS Blind Stored at Asset Domain Android Apps TikTok
XSS Blind Stored at Asset Domain Android Apps TikTok
Xss Attack

3 min read


May 28, 2022

The first XSS STORED find in YANDEX Bug Bounty Program

Assalamualaikum Bug Hunter & Hi Everyone. This time I want to share a finding of the XSS STORED Vulnerability on Yandex. Previously I have tried to search for vulnerabilities in the Yandex Bug Bounty Program, and as a result I did not find any vulnerabilities in Yandex. I was frustrated…

Xss Vulnerability

4 min read

The first XSS STORED find in YANDEX Bug Bounty Program
The first XSS STORED find in YANDEX Bug Bounty Program
Xss Vulnerability

4 min read


Mar 8, 2022

($$$) IDOR via GET Request which can SOLD all User Products

Hi everyone, In this article I want to share my findings on a Private Program at Hackerone which is very unique. Let’s take a minute to take a look at this :) When I was hunting on a private program on Hackerone, I came across a scope of https://redacted.com/. And…

Bug Bounty

2 min read

($$$) IDOR via GET Request which can SOLD all User Products
($$$) IDOR via GET Request which can SOLD all User Products
Bug Bounty

2 min read

Aidil Arief

Aidil Arief

619 Followers

Keep to secure the internet

Help

Status

About

Careers

Blog

Privacy

Terms

Text to speech

Teams