Back to directory
WRITEUP #4312

We Hacked Apple for 3 Months: Here’s What We Found

RCEAuthentication bypassAuthorization bypassSSRFXXEBlind XSSIDOROS command injectionSQL injection
by@samwcyo(Sam Curry)
Bounty
288,500
Program
Apple
Published
Oct 7, 2020
Added to HackDex
Nov 30, 2022
Read Full Writeuphttps://samcurry.net/hacking-apple/
RELATED WRITEUPS
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!
RCEConfusion attack
Directory Traversal, SQL Injection and Server-Side Request Forgery
SQL InjectionPath traversal
Vulnerabilities in Homepage Dashboard
RCESSRF
The Hunt for ALBeast: A Technical Walkthrough
CloudAWS ALB

Built with ❤️ by Shubham Rawat