Welcome to SecOne4All

Your destination for hacking tutorials, tools, and threat analysis.

Category: BugCrowd

How I discovered critical price manipulation

Hello Brothers, I hope you have a nice day. Today I will share how I discovered price manipulation. During my holiday, I started testing on a private program. The first thing I did was browse my target and try to discover the site’s features. After some time of browsing the target, I went to the […]

How I Used Reflected XSS + CORS + CSRF to Get 1-Click OAuth Misconfiguration

Hellllllllo brothers,Today I will show how I escalated Reflected XSS to One Click or even Zero Click ATO via escalating the XSS + CORS to OAuth Misconfiguration. While I was testing, I registered an account and started discovering and browsing all features on my target to better understand the target. During this process, I found […]