Feb. 8, 2023, 6:02 a.m. | ag3n7

InfoSec Write-ups - Medium infosecwriteups.com

First Bug Bounty

Openredirection + clickjacking + csrf -> Account Takeover

Bounty

Hola Hackers,

This writeup is about my first bug bounty in which the submission was duplicate, even though they rewarded me for chaining the bugs and reported it with an effective approach of a real-life attack scenario.

Let’s Start

First we will discuss about the bugs which I chained together.

Open Redirection
Open redirection vulnerabilities arise when an application incorporates user-controllable data into the target of a redirection …

account takeover bounty bug bug bounty bug-chaining bugs csrf vulnerability

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Physical Security Operations Center - Supervisor

@ Equifax | USA-GA-Alpharetta-JVW3

Network Cybersecurity Engineer - Overland Park, KS Hybrid

@ Black & Veatch | Overland Park, KS, US

Cloud Security Engineer

@ Point72 | United States

Technical Program Manager, Security and Compliance, Cloud Compute

@ Google | New York City, USA; Kirkland, WA, USA

EWT Security | Vulnerability Management Analyst - AM

@ KPMG India | Gurgaon, Haryana, India