@mabdullah22
25Undergrad Computer Engineering Student From Pakistan ,Interested in Hacking and Photography
steemit.com/@mabdullah22VOTING POWER100.00%
DOWNVOTE POWER100.00%
RESOURCE CREDITS100.00%
REPUTATION PROGRESS0.00%
Net Worth
0.273USD
STEEM
0.876STEEM
SBD
0.010SBD
Own SP
3.740SP
Detailed Balance
| STEEM | ||
| balance | 0.858STEEM | STEEM |
| market_balance | 0.000STEEM | STEEM |
| savings_balance | 0.000STEEM | STEEM |
| reward_steem_balance | 0.018STEEM | STEEM |
| STEEM POWER | ||
| Own SP | 3.740SP | SP |
| Delegated Out | 0.000SP | SP |
| Delegation In | 0.000SP | SP |
| Effective Power | 3.740SP | SP |
| Reward SP (pending) | 0.026SP | SP |
| SBD | ||
| sbd_balance | 0.000SBD | SBD |
| sbd_conversions | 0.000SBD | SBD |
| sbd_market_balance | 0.000SBD | SBD |
| savings_sbd_balance | 0.000SBD | SBD |
| reward_sbd_balance | 0.010SBD | SBD |
{
"balance": "0.858 STEEM",
"savings_balance": "0.000 STEEM",
"reward_steem_balance": "0.018 STEEM",
"vesting_shares": "6082.179841 VESTS",
"delegated_vesting_shares": "0.000000 VESTS",
"received_vesting_shares": "0.000000 VESTS",
"sbd_balance": "0.000 SBD",
"savings_sbd_balance": "0.000 SBD",
"reward_sbd_balance": "0.010 SBD",
"conversions": []
}Account Info
| name | mabdullah22 |
| id | 1080876 |
| rank | 982,516 |
| reputation | 689735915 |
| created | 2018-07-25T21:16:09 |
| recovery_account | blocktrades |
| proxy | None |
| post_count | 5 |
| comment_count | 0 |
| lifetime_vote_count | 0 |
| witnesses_voted_for | 0 |
| last_post | 2018-09-02T19:24:42 |
| last_root_post | 2018-09-02T19:24:42 |
| last_vote_time | 2018-07-27T21:17:57 |
| proxied_vsf_votes | 0, 0, 0, 0 |
| can_vote | 1 |
| voting_power | 9,052 |
| delayed_votes | 0 |
| balance | 0.858 STEEM |
| savings_balance | 0.000 STEEM |
| sbd_balance | 0.000 SBD |
| savings_sbd_balance | 0.000 SBD |
| vesting_shares | 6082.179841 VESTS |
| delegated_vesting_shares | 0.000000 VESTS |
| received_vesting_shares | 0.000000 VESTS |
| reward_vesting_balance | 52.693168 VESTS |
| vesting_balance | 0.000 STEEM |
| vesting_withdraw_rate | 0.000000 VESTS |
| next_vesting_withdrawal | 1969-12-31T23:59:59 |
| withdrawn | 0 |
| to_withdraw | 0 |
| withdraw_routes | 0 |
| savings_withdraw_requests | 0 |
| last_account_recovery | 1970-01-01T00:00:00 |
| reset_account | null |
| last_owner_update | 1970-01-01T00:00:00 |
| last_account_update | 2018-07-26T11:00:39 |
| mined | No |
| sbd_seconds | 0 |
| sbd_last_interest_payment | 1970-01-01T00:00:00 |
| savings_sbd_last_interest_payment | 1970-01-01T00:00:00 |
{
"id": 1080876,
"name": "mabdullah22",
"owner": {
"weight_threshold": 1,
"account_auths": [],
"key_auths": [
[
"STM8jEN9rHcUDRSdaqwhbit3Z2t9jzcC9Jvsz7BELmB2oEmtkayUM",
1
]
]
},
"active": {
"weight_threshold": 1,
"account_auths": [],
"key_auths": [
[
"STM6gVXGHnRQLMWHS7bBTyGRJgeseVqGsaTpNbjX8goYYXF4ygaMc",
1
]
]
},
"posting": {
"weight_threshold": 1,
"account_auths": [
[
"steem.app",
1
]
],
"key_auths": [
[
"STM6LCLT9whkfjYZTyB7hCUYXUhTFEyHbGkXjNowLpjQWareDxyBr",
1
]
]
},
"memo_key": "STM6FBAxt6yNU1wULZpmUy4CUcn92pMRWZ5HTfFgCLJSPP9BwZ3qJ",
"json_metadata": "{\"profile\":{\"profile_image\":\"https://cdn.steemitimages.com/DQmZTZdNU9eVrZz5FeFJKDoRWrd3a96euu8ZpB76AVsA46E/DSC_0514.jpg\",\"name\":\"Muhammad Abdullah\",\"about\":\"Undergrad Computer Engineering Student From Pakistan ,Interested in Hacking and Photography\"}}",
"posting_json_metadata": "{\"profile\":{\"profile_image\":\"https://cdn.steemitimages.com/DQmZTZdNU9eVrZz5FeFJKDoRWrd3a96euu8ZpB76AVsA46E/DSC_0514.jpg\",\"name\":\"Muhammad Abdullah\",\"about\":\"Undergrad Computer Engineering Student From Pakistan ,Interested in Hacking and Photography\"}}",
"proxy": "",
"last_owner_update": "1970-01-01T00:00:00",
"last_account_update": "2018-07-26T11:00:39",
"created": "2018-07-25T21:16:09",
"mined": false,
"recovery_account": "blocktrades",
"last_account_recovery": "1970-01-01T00:00:00",
"reset_account": "null",
"comment_count": 0,
"lifetime_vote_count": 0,
"post_count": 5,
"can_vote": true,
"voting_manabar": {
"current_mana": 9052,
"last_update_time": 1532726277
},
"downvote_manabar": {
"current_mana": 0,
"last_update_time": 1532553369
},
"voting_power": 9052,
"balance": "0.858 STEEM",
"savings_balance": "0.000 STEEM",
"sbd_balance": "0.000 SBD",
"sbd_seconds": "0",
"sbd_seconds_last_update": "1970-01-01T00:00:00",
"sbd_last_interest_payment": "1970-01-01T00:00:00",
"savings_sbd_balance": "0.000 SBD",
"savings_sbd_seconds": "0",
"savings_sbd_seconds_last_update": "1970-01-01T00:00:00",
"savings_sbd_last_interest_payment": "1970-01-01T00:00:00",
"savings_withdraw_requests": 0,
"reward_sbd_balance": "0.010 SBD",
"reward_steem_balance": "0.018 STEEM",
"reward_vesting_balance": "52.693168 VESTS",
"reward_vesting_steem": "0.026 STEEM",
"vesting_shares": "6082.179841 VESTS",
"delegated_vesting_shares": "0.000000 VESTS",
"received_vesting_shares": "0.000000 VESTS",
"vesting_withdraw_rate": "0.000000 VESTS",
"next_vesting_withdrawal": "1969-12-31T23:59:59",
"withdrawn": 0,
"to_withdraw": 0,
"withdraw_routes": 0,
"curation_rewards": 0,
"posting_rewards": 52,
"proxied_vsf_votes": [
0,
0,
0,
0
],
"witnesses_voted_for": 0,
"last_post": "2018-09-02T19:24:42",
"last_root_post": "2018-09-02T19:24:42",
"last_vote_time": "2018-07-27T21:17:57",
"post_bandwidth": 0,
"pending_claimed_accounts": 0,
"vesting_balance": "0.000 STEEM",
"reputation": 689735915,
"transfer_history": [],
"market_history": [],
"post_history": [],
"vote_history": [],
"other_history": [],
"witness_votes": [],
"tags_usage": [],
"guest_bloggers": [],
"rank": 982516
}Withdraw Routes
| Incoming | Outgoing |
|---|---|
Empty | Empty |
{
"incoming": [],
"outgoing": []
}From Date
To Date
2019/07/25 22:43:57
2019/07/25 22:43:57
| parent author | mabdullah22 |
| parent permlink | i-own-your-customers |
| author | steemitboard |
| permlink | steemitboard-notify-mabdullah22-20190725t224357000z |
| title | |
| body | Congratulations @mabdullah22! You received a personal award! <table><tr><td>https://steemitimages.com/70x70/http://steemitboard.com/@mabdullah22/birthday1.png</td><td>Happy Birthday! - You are on the Steem blockchain for 1 year!</td></tr></table> <sub>_You can view [your badges on your Steem Board](https://steemitboard.com/@mabdullah22) and compare to others on the [Steem Ranking](https://steemitboard.com/ranking/index.php?name=mabdullah22)_</sub> ###### [Vote for @Steemitboard as a witness](https://v2.steemconnect.com/sign/account-witness-vote?witness=steemitboard&approve=1) to get one more award and increased upvotes! |
| json metadata | {"image":["https://steemitboard.com/img/notify.png"]} |
| Transaction Info | Block #34983145/Trx 8f5d48c1cc33dc5413b2a6b394e4b6af5496262e |
View Raw JSON Data
{
"trx_id": "8f5d48c1cc33dc5413b2a6b394e4b6af5496262e",
"block": 34983145,
"trx_in_block": 9,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2019-07-25T22:43:57",
"op": [
"comment",
{
"parent_author": "mabdullah22",
"parent_permlink": "i-own-your-customers",
"author": "steemitboard",
"permlink": "steemitboard-notify-mabdullah22-20190725t224357000z",
"title": "",
"body": "Congratulations @mabdullah22! You received a personal award!\n\n<table><tr><td>https://steemitimages.com/70x70/http://steemitboard.com/@mabdullah22/birthday1.png</td><td>Happy Birthday! - You are on the Steem blockchain for 1 year!</td></tr></table>\n\n<sub>_You can view [your badges on your Steem Board](https://steemitboard.com/@mabdullah22) and compare to others on the [Steem Ranking](https://steemitboard.com/ranking/index.php?name=mabdullah22)_</sub>\n\n\n###### [Vote for @Steemitboard as a witness](https://v2.steemconnect.com/sign/account-witness-vote?witness=steemitboard&approve=1) to get one more award and increased upvotes!",
"json_metadata": "{\"image\":[\"https://steemitboard.com/img/notify.png\"]}"
}
]
}ax3upvoted (1.00%) @mabdullah22 / i-own-your-customers2018/09/02 19:24:51
ax3upvoted (1.00%) @mabdullah22 / i-own-your-customers
2018/09/02 19:24:51
| voter | ax3 |
| author | mabdullah22 |
| permlink | i-own-your-customers |
| weight | 100 (1.00%) |
| Transaction Info | Block #25615562/Trx 2e09c1c1c5e9e3a559711107ab1630a1ff8e2cb8 |
View Raw JSON Data
{
"trx_id": "2e09c1c1c5e9e3a559711107ab1630a1ff8e2cb8",
"block": 25615562,
"trx_in_block": 47,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-09-02T19:24:51",
"op": [
"vote",
{
"voter": "ax3",
"author": "mabdullah22",
"permlink": "i-own-your-customers",
"weight": 100
}
]
}mabdullah22published a new post: i-own-your-customers2018/09/02 19:24:42
mabdullah22published a new post: i-own-your-customers
2018/09/02 19:24:42
| parent author | |
| parent permlink | blockchain |
| author | mabdullah22 |
| permlink | i-own-your-customers |
| title | I Own Your Customers !!! |
| body | Hi This is my second write-up related to cryptoExchange Hacks.Last time I hacked an Exchange using IDOR vulnerability in Password Reset Function(Writeup here). This time it was something very interesting which I found.This lead me to access all the KYC documents of Users. # Background Story: So these days I am not doing hunting much ,rather I am learning DPDK(Data Plane Development Kit) which is a Development kit by Intel to do fast packet processing.As much tutorials are not available on this so one has to goto whole documentation to learn.Btw Intel has a very Good documentation on DPDK.So fed up with reading documentation ,I wanted to relax myself.Earning some bounties was the way :p So Basically I got access to all the KYC documents of Users of two projects by accessing the s3 Buckets.I will not be disclosing the names of the project.But one is a CryptoExchange with a good volume.Other is a Blockchain project backed by some reputable names in Crypto community. # 1.Blockchain Project Every time I start testing a website.My first step is to do recon on it as everyone does.So I fired up my subdomain recon scripts and found the following.  The one which looked interesting to me was (120185.xyz.com). Turns out this was the admin panel of the website.So I started trying to bypass the admin panel with different tricks.I don’t have the screenshot of Admin panel right now as they have taken it down.So after trying for an hour hopelessly I turned to Burp to see the site’s spidered structure.I started reading the js files which were accessible on the panel. https://120185.xyz.com/js/app-1eda861a990702514571.bundle.js While reading the file I found this.  This got my attention and I searched for keyword bucket.And what I found shocked me.Hardcoded AWS credentials of a bucket.  I used the credentials to access the S3 bucket.User Kyc docs were uploaded into the bucket.I had access to thousand of KYC Docs.  I didn’t downloaded any Doc being Ethical.And reported it to organization ASAP.They quickly implemented the fix. ## Takeaways: -Always read the Javascript files ,you might get lucky. ## Timeline: August 29.2018 12:57 PM -> Report Sent August 29,2018 7:30 PM ->Checked and Bug is Fixed # 2.CryptoExchange I guess this is one of the easiest bug I found and was handsomely rewarded.I won’t be disclosing the exchange name ,lets call it vuln.com. I had no intentions of hunting this exchange.I visited this exchange to see the exchange rate of a token in which I had invested.Out of now where I opened the source code of the exchange.And I found this.  Upon viewing this my inside Hacker instinct got awaken.And I opened the s3 bucket.The bucket was readable.What I found next was astonishing.Whole KYC Documents here too.Plus support ticket documents too.    ## Take Away: ~Do look at the source code. ~Always Check the Buckets you never know what juicy info you can get. ## Timeline: August 30,2018 1:12 PM -> Report sent August 30,2018 4:00 PM -> Bug Fixed August 30,2018 5:07PM -> Bounty Rewarded (10 ETH) |
| json metadata | {"tags":["blockchain","cryptoexchange","crypto","hacking","security"],"image":["https://cdn.steemitimages.com/DQmRW9MQJzX2ikFDbDE3cyqDzH2CiGxSBB7ham1T2irEjsC/subdomains.PNG","https://cdn.steemitimages.com/DQmPkJJLkf9SM12Ly1kq6nP32AryGBbJrhg1hCZQAbYQMru/b1.PNG","https://cdn.steemitimages.com/DQmSzhQ1F6Dee3CFmScEQMY5Q5CVp8yK4d8Ar1txbY6bsKQ/b2.PNG","https://cdn.steemitimages.com/DQmTaGk5aUVizmJ5oB4DybyUXJ7iahz4JDEqC41pruEQuX4/aws.PNG","https://cdn.steemitimages.com/DQmeapaM9aMuCTzPk2XjG7pvTcTBJ9vjRteWUYBqjucFPrY/srcode.PNG","https://cdn.steemitimages.com/DQmfUHVDNifMvxwfkv8XSGJYpfgBCXsEKZ4zi7SazJoDJdt/list%20buckets.png","https://cdn.steemitimages.com/DQmagavSNFrxjZCfmtyMZT6ws4dgKtW7nKkWiRUoSgANmUv/identity_docs.png","https://cdn.steemitimages.com/DQmcDZaPGDaN82N6HBR9UhADjDcmzcamHc778uASe5DBdtX/email.PNG"],"links":["https://120185.xyz.com/js/app-1eda861a990702514571.bundle.js"],"app":"steemit/0.1","format":"markdown"} |
| Transaction Info | Block #25615559/Trx 1d052c849baa3e35580257e42f973ed75c4e8263 |
View Raw JSON Data
{
"trx_id": "1d052c849baa3e35580257e42f973ed75c4e8263",
"block": 25615559,
"trx_in_block": 0,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-09-02T19:24:42",
"op": [
"comment",
{
"parent_author": "",
"parent_permlink": "blockchain",
"author": "mabdullah22",
"permlink": "i-own-your-customers",
"title": "I Own Your Customers !!!",
"body": "Hi\nThis is my second write-up related to cryptoExchange Hacks.Last time I hacked an Exchange using IDOR vulnerability in Password Reset Function(Writeup here). This time it was something very interesting which I found.This lead me to access all the KYC documents of Users.\n\n# Background Story:\nSo these days I am not doing hunting much ,rather I am learning DPDK(Data Plane Development Kit) which is a Development kit by Intel to do fast packet processing.As much tutorials are not available on this so one has to goto whole documentation to learn.Btw Intel has a very Good documentation on DPDK.So fed up with reading documentation ,I wanted to relax myself.Earning some bounties was the way :p\n\nSo Basically I got access to all the KYC documents of Users of two projects by accessing the s3 Buckets.I will not be disclosing the names of the project.But one is a CryptoExchange with a good volume.Other is a Blockchain project backed by some reputable names in Crypto community.\n\n# 1.Blockchain Project\nEvery time I start testing a website.My first step is to do recon on it as everyone does.So I fired up my subdomain recon scripts and found the following.\n\n\n\nThe one which looked interesting to me was (120185.xyz.com). Turns out this was the admin panel of the website.So I started trying to bypass the admin panel with different tricks.I don’t have the screenshot of Admin panel right now as they have taken it down.So after trying for an hour hopelessly I turned to Burp to see the site’s spidered structure.I started reading the js files which were accessible on the panel.\n\nhttps://120185.xyz.com/js/app-1eda861a990702514571.bundle.js\n\nWhile reading the file I found this.\n\n\n\nThis got my attention and I searched for keyword bucket.And what I found shocked me.Hardcoded AWS credentials of a bucket.\n\n\n\nI used the credentials to access the S3 bucket.User Kyc docs were uploaded into the bucket.I had access to thousand of KYC Docs.\n\n\n\nI didn’t downloaded any Doc being Ethical.And reported it to organization ASAP.They quickly implemented the fix.\n\n## Takeaways:\n-Always read the Javascript files ,you might get lucky.\n\n## Timeline:\nAugust 29.2018 12:57 PM -> Report Sent\nAugust 29,2018 7:30 PM ->Checked and Bug is Fixed\n\n# 2.CryptoExchange\nI guess this is one of the easiest bug I found and was handsomely rewarded.I won’t be disclosing the exchange name ,lets call it vuln.com.\n\nI had no intentions of hunting this exchange.I visited this exchange to see the exchange rate of a token in which I had invested.Out of now where I opened the source code of the exchange.And I found this.\n\n\n\nUpon viewing this my inside Hacker instinct got awaken.And I opened the s3 bucket.The bucket was readable.What I found next was astonishing.Whole KYC Documents here too.Plus support ticket documents too.\n\n\n\n\n\n\n\n## Take Away:\n~Do look at the source code.\n~Always Check the Buckets you never know what juicy info you can get.\n\n## Timeline:\nAugust 30,2018 1:12 PM -> Report sent\nAugust 30,2018 4:00 PM -> Bug Fixed\nAugust 30,2018 5:07PM -> Bounty Rewarded (10 ETH)",
"json_metadata": "{\"tags\":[\"blockchain\",\"cryptoexchange\",\"crypto\",\"hacking\",\"security\"],\"image\":[\"https://cdn.steemitimages.com/DQmRW9MQJzX2ikFDbDE3cyqDzH2CiGxSBB7ham1T2irEjsC/subdomains.PNG\",\"https://cdn.steemitimages.com/DQmPkJJLkf9SM12Ly1kq6nP32AryGBbJrhg1hCZQAbYQMru/b1.PNG\",\"https://cdn.steemitimages.com/DQmSzhQ1F6Dee3CFmScEQMY5Q5CVp8yK4d8Ar1txbY6bsKQ/b2.PNG\",\"https://cdn.steemitimages.com/DQmTaGk5aUVizmJ5oB4DybyUXJ7iahz4JDEqC41pruEQuX4/aws.PNG\",\"https://cdn.steemitimages.com/DQmeapaM9aMuCTzPk2XjG7pvTcTBJ9vjRteWUYBqjucFPrY/srcode.PNG\",\"https://cdn.steemitimages.com/DQmfUHVDNifMvxwfkv8XSGJYpfgBCXsEKZ4zi7SazJoDJdt/list%20buckets.png\",\"https://cdn.steemitimages.com/DQmagavSNFrxjZCfmtyMZT6ws4dgKtW7nKkWiRUoSgANmUv/identity_docs.png\",\"https://cdn.steemitimages.com/DQmcDZaPGDaN82N6HBR9UhADjDcmzcamHc778uASe5DBdtX/email.PNG\"],\"links\":[\"https://120185.xyz.com/js/app-1eda861a990702514571.bundle.js\"],\"app\":\"steemit/0.1\",\"format\":\"markdown\"}"
}
]
}mabdullah22received 0.018 STEEM, 0.010 SBD, 0.032 SP author reward for @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/08/01 21:38:24
mabdullah22received 0.018 STEEM, 0.010 SBD, 0.032 SP author reward for @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/08/01 21:38:24
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| sbd payout | 0.010 SBD |
| steem payout | 0.018 STEEM |
| vesting payout | 52.693168 VESTS |
| Transaction Info | Block #24697020/Virtual Operation #23 |
View Raw JSON Data
{
"trx_id": "0000000000000000000000000000000000000000",
"block": 24697020,
"trx_in_block": 4294967295,
"op_in_trx": 0,
"virtual_op": 23,
"timestamp": "2018-08-01T21:38:24",
"op": [
"author_reward",
{
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"sbd_payout": "0.010 SBD",
"steem_payout": "0.018 STEEM",
"vesting_payout": "52.693168 VESTS"
}
]
}2018/07/27 22:32:33
2018/07/27 22:32:33
| parent author | mabdullah22 |
| parent permlink | feeding-yourself-is-hard-old-man-in-a-market |
| author | photocontests3 |
| permlink | re-feeding-yourself-is-hard-old-man-in-a-market-20180727t223229 |
| title | |
| body | <b>World of Photography</b><br><a href="http://worldofphotography.org">>Visit the website<</a><br><br>You have earned <b>6.50 XP</b> for sharing your photo! <br><table><tr><td><b>Daily Stats</b><br>Daily photos: 1/2 <br> Daily comments: 0/5<br>Multiplier: 1.30<br><sub>Block time: 2018-07-27T22:31:33</sub></td><td><b>Account Level: 0</b><br>Total XP: 6.50/100.00<br>Total Photos: 1<br>Total comments: 0<br> Total contest wins: 0</td></tr></table>When you reach level 1 you will start receiving up to two daily upvotes<br><br> <b>Follow:</b> @photocontests<br><b>Join the Discord channel:</b> <a href="https://discord.gg/2pmd5Dr">click!</a><br><b>Play and win SBD: </b>@fairlotto<br><b>Daily Steem Statistics: </b>@dailysteemreport<br><b>Learn how to program Steem-Python applications: </b>@steempytutorials<br><b>Developed and sponsored by:</b> @juliank |
| json metadata | |
| Transaction Info | Block #24554595/Trx 3dba2d5341a148c149d2d5920163b16006cd1988 |
View Raw JSON Data
{
"trx_id": "3dba2d5341a148c149d2d5920163b16006cd1988",
"block": 24554595,
"trx_in_block": 51,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T22:32:33",
"op": [
"comment",
{
"parent_author": "mabdullah22",
"parent_permlink": "feeding-yourself-is-hard-old-man-in-a-market",
"author": "photocontests3",
"permlink": "re-feeding-yourself-is-hard-old-man-in-a-market-20180727t223229",
"title": "",
"body": "<b>World of Photography</b><br><a href=\"http://worldofphotography.org\">>Visit the website<</a><br><br>You have earned <b>6.50 XP</b> for sharing your photo! <br><table><tr><td><b>Daily Stats</b><br>Daily photos: 1/2 <br> Daily comments: 0/5<br>Multiplier: 1.30<br><sub>Block time: 2018-07-27T22:31:33</sub></td><td><b>Account Level: 0</b><br>Total XP: 6.50/100.00<br>Total Photos: 1<br>Total comments: 0<br> Total contest wins: 0</td></tr></table>When you reach level 1 you will start receiving up to two daily upvotes<br><br> <b>Follow:</b> @photocontests<br><b>Join the Discord channel:</b> <a href=\"https://discord.gg/2pmd5Dr\">click!</a><br><b>Play and win SBD: </b>@fairlotto<br><b>Daily Steem Statistics: </b>@dailysteemreport<br><b>Learn how to program Steem-Python applications: </b>@steempytutorials<br><b>Developed and sponsored by:</b> @juliank",
"json_metadata": ""
}
]
}mabdullah22published a new post: feeding-yourself-is-hard-old-man-in-a-market2018/07/27 22:31:30
mabdullah22published a new post: feeding-yourself-is-hard-old-man-in-a-market
2018/07/27 22:31:30
| parent author | |
| parent permlink | streetphotography |
| author | mabdullah22 |
| permlink | feeding-yourself-is-hard-old-man-in-a-market |
| title | Feeding Yourself is Hard : Old man in a market |
| body | From the photograph it is clear that its Afternoon.A man caring boxes on his back in the scorching heat of sun.The old man looks in his 70s.A age where he should he resting in his home.Rather he is picking boxes on his weak back in market.  Hunger makes you do anything.And earning money is hard.In Pakistan the average salary of a Daily Labor is around 300-500 Rupees ,that's around 3-4 USD. You can imagine how hard it can be for labor to feed himself and his family.And sometimes they don't get work at all.   ## Location These photograph were taken at a Local market in Rawalpindi ,Pakistan. ## Equipment Nikon D7100 17-140 mm Lens |
| json metadata | {"tags":["streetphotography","photography","photo","life","pakistan"],"image":["https://cdn.steemitimages.com/DQmdwhQ6fLCWvBXxCh4q1q5CdjotWGSx3e983fB6vofjrqz/DSC_0111.jpg","https://cdn.steemitimages.com/DQmTKqQgjqc4e6xfCAxZPNazCxcx3adBqK1rPt4J21eMnoV/DSC_0110.jpg","https://cdn.steemitimages.com/DQmNjuFMbfRA3JM4U2SwPZjn5JbLqbKoATiercokhPFKWyg/DSC_0107.jpg"],"app":"steemit/0.1","format":"markdown"} |
| Transaction Info | Block #24554574/Trx 21b830ffd9a5aaa61a83505de921b6a72886168d |
View Raw JSON Data
{
"trx_id": "21b830ffd9a5aaa61a83505de921b6a72886168d",
"block": 24554574,
"trx_in_block": 43,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T22:31:30",
"op": [
"comment",
{
"parent_author": "",
"parent_permlink": "streetphotography",
"author": "mabdullah22",
"permlink": "feeding-yourself-is-hard-old-man-in-a-market",
"title": "Feeding Yourself is Hard : Old man in a market",
"body": "From the photograph it is clear that its Afternoon.A man caring boxes on his back in the scorching heat of sun.The old man looks in his 70s.A age where he should he resting in his home.Rather he is picking boxes on his weak back in market.\n\n \n\nHunger makes you do anything.And earning money is hard.In Pakistan the average salary of a Daily Labor is around 300-500 Rupees ,that's around 3-4 USD. You can imagine how hard it can be for labor to feed himself and his family.And sometimes they don't get work at all.\n\n\n\n\n\n\n\n## Location\nThese photograph were taken at a Local market in Rawalpindi ,Pakistan.\n\n## Equipment\nNikon D7100\n17-140 mm Lens",
"json_metadata": "{\"tags\":[\"streetphotography\",\"photography\",\"photo\",\"life\",\"pakistan\"],\"image\":[\"https://cdn.steemitimages.com/DQmdwhQ6fLCWvBXxCh4q1q5CdjotWGSx3e983fB6vofjrqz/DSC_0111.jpg\",\"https://cdn.steemitimages.com/DQmTKqQgjqc4e6xfCAxZPNazCxcx3adBqK1rPt4J21eMnoV/DSC_0110.jpg\",\"https://cdn.steemitimages.com/DQmNjuFMbfRA3JM4U2SwPZjn5JbLqbKoATiercokhPFKWyg/DSC_0107.jpg\"],\"app\":\"steemit/0.1\",\"format\":\"markdown\"}"
}
]
}mabdullah22upvoted (100.00%) @faady92 / blood-moon-eclipse-sighted-in-pakistan-2018-07-27-20-12-052018/07/27 21:17:57
mabdullah22upvoted (100.00%) @faady92 / blood-moon-eclipse-sighted-in-pakistan-2018-07-27-20-12-05
2018/07/27 21:17:57
| voter | mabdullah22 |
| author | faady92 |
| permlink | blood-moon-eclipse-sighted-in-pakistan-2018-07-27-20-12-05 |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24553103/Trx 264f00bc2d6efeaa7aa51e4697bf95a8cf48421e |
View Raw JSON Data
{
"trx_id": "264f00bc2d6efeaa7aa51e4697bf95a8cf48421e",
"block": 24553103,
"trx_in_block": 35,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T21:17:57",
"op": [
"vote",
{
"voter": "mabdullah22",
"author": "faady92",
"permlink": "blood-moon-eclipse-sighted-in-pakistan-2018-07-27-20-12-05",
"weight": 10000
}
]
}mabdullah22upvoted (100.00%) @mrogy1 / p-h-o-t-o-g-r-a-p-h-y-e247b74a528be2018/07/27 21:17:36
mabdullah22upvoted (100.00%) @mrogy1 / p-h-o-t-o-g-r-a-p-h-y-e247b74a528be
2018/07/27 21:17:36
| voter | mabdullah22 |
| author | mrogy1 |
| permlink | p-h-o-t-o-g-r-a-p-h-y-e247b74a528be |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24553096/Trx 1180fb9afbf327a90cb3e6956011790674a4de54 |
View Raw JSON Data
{
"trx_id": "1180fb9afbf327a90cb3e6956011790674a4de54",
"block": 24553096,
"trx_in_block": 8,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T21:17:36",
"op": [
"vote",
{
"voter": "mabdullah22",
"author": "mrogy1",
"permlink": "p-h-o-t-o-g-r-a-p-h-y-e247b74a528be",
"weight": 10000
}
]
}mabdullah22upvoted (100.00%) @hectorro / eclipse-lunar-today-july-27-20182018/07/27 21:16:57
mabdullah22upvoted (100.00%) @hectorro / eclipse-lunar-today-july-27-2018
2018/07/27 21:16:57
| voter | mabdullah22 |
| author | hectorro |
| permlink | eclipse-lunar-today-july-27-2018 |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24553083/Trx 521ac0b03dab896e78fcb64442f7606f5f59373b |
View Raw JSON Data
{
"trx_id": "521ac0b03dab896e78fcb64442f7606f5f59373b",
"block": 24553083,
"trx_in_block": 26,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T21:16:57",
"op": [
"vote",
{
"voter": "mabdullah22",
"author": "hectorro",
"permlink": "eclipse-lunar-today-july-27-2018",
"weight": 10000
}
]
}mabdullah22followed @spacexx2018/07/27 21:16:09
mabdullah22followed @spacexx
2018/07/27 21:16:09
| required auths | [] |
| required posting auths | ["mabdullah22"] |
| id | follow |
| json | ["follow",{"follower":"mabdullah22","following":"spacexx","what":["blog"]}] |
| Transaction Info | Block #24553067/Trx 9e9daa7ee618bbd0f84129e1a9dc7fca52f271ad |
View Raw JSON Data
{
"trx_id": "9e9daa7ee618bbd0f84129e1a9dc7fca52f271ad",
"block": 24553067,
"trx_in_block": 12,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T21:16:09",
"op": [
"custom_json",
{
"required_auths": [],
"required_posting_auths": [
"mabdullah22"
],
"id": "follow",
"json": "[\"follow\",{\"follower\":\"mabdullah22\",\"following\":\"spacexx\",\"what\":[\"blog\"]}]"
}
]
}mabdullah22upvoted (100.00%) @spacexx / bitcoin-price-analysis-july-27-20182018/07/27 21:15:57
mabdullah22upvoted (100.00%) @spacexx / bitcoin-price-analysis-july-27-2018
2018/07/27 21:15:57
| voter | mabdullah22 |
| author | spacexx |
| permlink | bitcoin-price-analysis-july-27-2018 |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24553063/Trx 958fc54fd4e705253b96318635f5159075081f45 |
View Raw JSON Data
{
"trx_id": "958fc54fd4e705253b96318635f5159075081f45",
"block": 24553063,
"trx_in_block": 8,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T21:15:57",
"op": [
"vote",
{
"voter": "mabdullah22",
"author": "spacexx",
"permlink": "bitcoin-price-analysis-july-27-2018",
"weight": 10000
}
]
}2018/07/27 21:05:03
2018/07/27 21:05:03
| voter | mabdullah22 |
| author | redouanemez |
| permlink | earn-up-to-160-usd-i-really-earn-80-usd-do-not-miss-this-opportunity-27-07-2018 |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24552845/Trx 0752fc7b4f41605a489c33acdb89324f7138a02e |
View Raw JSON Data
{
"trx_id": "0752fc7b4f41605a489c33acdb89324f7138a02e",
"block": 24552845,
"trx_in_block": 9,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T21:05:03",
"op": [
"vote",
{
"voter": "mabdullah22",
"author": "redouanemez",
"permlink": "earn-up-to-160-usd-i-really-earn-80-usd-do-not-miss-this-opportunity-27-07-2018",
"weight": 10000
}
]
}mabdullah22published a new post: 200usd-made-in-20-mintues2018/07/27 20:47:42
mabdullah22published a new post: 200usd-made-in-20-mintues
2018/07/27 20:47:42
| parent author | |
| parent permlink | money |
| author | mabdullah22 |
| permlink | 200usd-made-in-20-mintues |
| title | 200$ made in 20 Mintues |
| body | This is the story about my fastest Bounty which I got on Hackerone Platform.This happened about 1 year ago ,when I got a Private Invite from Showmax. Program is now Public ## Showmax Showmax is an online subscription video on demand (SVOD) service which launched in South Africa on 19 August 2015. ## Vulnerability So As ususal I started Enumerating the Subdomains And Fired up Sublist3r.I got some domains and started testing them. One domain that Caught my eye was SSO.showmax.com. On sso.showmax.com there was only a login form. When a user entered wrong logins he/she was shown a failure message.This message parameter was vulnerable to XSS and injection issues. https://sso.showmax.com/auth/failure?message=PAYLOAD&strategy=ldap  ## TakeAways ~ Test every Parameter you get ## Time-Line May. 9, 2017 → Initial Report Sent on H1 May. 9, 2017 → Triage within 10 mins May. 9, 2017 → Fixed within 10 mins May. 9, 2017 → Bounty Awarded |
| json metadata | {"tags":["money","security","bugbounty","infosec","steemit"],"image":["https://cdn.steemitimages.com/DQmRsRmvPCwT3esF7wxFEqiegRWXsZgbLSSfuccqwSUdhji/showmax.PNG"],"links":["https://sso.showmax.com/auth/failure?message=PAYLOAD&strategy=ldap"],"app":"steemit/0.1","format":"markdown"} |
| Transaction Info | Block #24552498/Trx 7dd536f340ad2eaa06ac6fde9e76ae50cc193554 |
View Raw JSON Data
{
"trx_id": "7dd536f340ad2eaa06ac6fde9e76ae50cc193554",
"block": 24552498,
"trx_in_block": 15,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T20:47:42",
"op": [
"comment",
{
"parent_author": "",
"parent_permlink": "money",
"author": "mabdullah22",
"permlink": "200usd-made-in-20-mintues",
"title": "200$ made in 20 Mintues",
"body": "This is the story about my fastest Bounty which I got on Hackerone Platform.This happened about 1 year ago ,when I got a Private Invite from Showmax. Program is now Public\n\n## Showmax\nShowmax is an online subscription video on demand (SVOD) service which launched in South Africa on 19 August 2015.\n\n## Vulnerability\nSo As ususal I started Enumerating the Subdomains And Fired up Sublist3r.I got some domains and started testing them.\n\nOne domain that Caught my eye was SSO.showmax.com.\n\nOn sso.showmax.com there was only a login form.\n\nWhen a user entered wrong logins he/she was shown a failure message.This message parameter was vulnerable to XSS and injection issues.\n\nhttps://sso.showmax.com/auth/failure?message=PAYLOAD&strategy=ldap\n\n\n\n\n\n\n## TakeAways\n~ Test every Parameter you get \n\n## Time-Line\nMay. 9, 2017 → Initial Report Sent on H1\nMay. 9, 2017 → Triage within 10 mins\n\nMay. 9, 2017 → Fixed within 10 mins\nMay. 9, 2017 → Bounty Awarded",
"json_metadata": "{\"tags\":[\"money\",\"security\",\"bugbounty\",\"infosec\",\"steemit\"],\"image\":[\"https://cdn.steemitimages.com/DQmRsRmvPCwT3esF7wxFEqiegRWXsZgbLSSfuccqwSUdhji/showmax.PNG\"],\"links\":[\"https://sso.showmax.com/auth/failure?message=PAYLOAD&strategy=ldap\"],\"app\":\"steemit/0.1\",\"format\":\"markdown\"}"
}
]
}moneyguruuupvoted (42.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/07/27 19:33:27
moneyguruuupvoted (42.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/07/27 19:33:27
| voter | moneyguruu |
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| weight | 4200 (42.00%) |
| Transaction Info | Block #24551013/Trx c62de80aa69f0090f5dd59fe41917c2813261f38 |
View Raw JSON Data
{
"trx_id": "c62de80aa69f0090f5dd59fe41917c2813261f38",
"block": 24551013,
"trx_in_block": 19,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T19:33:27",
"op": [
"vote",
{
"voter": "moneyguruu",
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"weight": 4200
}
]
}payelmiaupvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/07/27 14:35:33
payelmiaupvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/07/27 14:35:33
| voter | payelmia |
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24545056/Trx 331c7731a8d63fa8ec4615ab50bffd9180071d08 |
View Raw JSON Data
{
"trx_id": "331c7731a8d63fa8ec4615ab50bffd9180071d08",
"block": 24545056,
"trx_in_block": 28,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T14:35:33",
"op": [
"vote",
{
"voter": "payelmia",
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"weight": 10000
}
]
}scimyworldupvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/07/27 09:34:30
scimyworldupvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/07/27 09:34:30
| voter | scimyworld |
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24539035/Trx 108c50afe27e86536095a7f312d24037309d97de |
View Raw JSON Data
{
"trx_id": "108c50afe27e86536095a7f312d24037309d97de",
"block": 24539035,
"trx_in_block": 36,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T09:34:30",
"op": [
"vote",
{
"voter": "scimyworld",
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"weight": 10000
}
]
}ambika138upvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/07/27 07:05:42
ambika138upvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/07/27 07:05:42
| voter | ambika138 |
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24536059/Trx c7b27c1e02673efcfab0c8d6e7a4d310aeda8a1f |
View Raw JSON Data
{
"trx_id": "c7b27c1e02673efcfab0c8d6e7a4d310aeda8a1f",
"block": 24536059,
"trx_in_block": 21,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T07:05:42",
"op": [
"vote",
{
"voter": "ambika138",
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"weight": 10000
}
]
}kate-nakamotoupvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/07/27 06:17:18
kate-nakamotoupvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/07/27 06:17:18
| voter | kate-nakamoto |
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24535091/Trx 95cc0cb074ba274fa48663ab6f9962e079a0cb0c |
View Raw JSON Data
{
"trx_id": "95cc0cb074ba274fa48663ab6f9962e079a0cb0c",
"block": 24535091,
"trx_in_block": 58,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T06:17:18",
"op": [
"vote",
{
"voter": "kate-nakamoto",
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"weight": 10000
}
]
}dion66upvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/07/27 05:58:51
dion66upvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/07/27 05:58:51
| voter | dion66 |
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24534722/Trx 3e1e8aa549a75b0456cf799d5ec84f31c6b0abd7 |
View Raw JSON Data
{
"trx_id": "3e1e8aa549a75b0456cf799d5ec84f31c6b0abd7",
"block": 24534722,
"trx_in_block": 15,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T05:58:51",
"op": [
"vote",
{
"voter": "dion66",
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"weight": 10000
}
]
}sujon123upvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/07/27 04:15:33
sujon123upvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/07/27 04:15:33
| voter | sujon123 |
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24532661/Trx 6222234474064ab61cdc4e765c5464e5cedabbe6 |
View Raw JSON Data
{
"trx_id": "6222234474064ab61cdc4e765c5464e5cedabbe6",
"block": 24532661,
"trx_in_block": 18,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T04:15:33",
"op": [
"vote",
{
"voter": "sujon123",
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"weight": 10000
}
]
}akhileshbhaiupvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/07/27 02:34:45
akhileshbhaiupvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/07/27 02:34:45
| voter | akhileshbhai |
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24530649/Trx 7ea792a820f060cae90c4881afda2231f713fb9f |
View Raw JSON Data
{
"trx_id": "7ea792a820f060cae90c4881afda2231f713fb9f",
"block": 24530649,
"trx_in_block": 9,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T02:34:45",
"op": [
"vote",
{
"voter": "akhileshbhai",
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"weight": 10000
}
]
}kellancoinupvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/07/27 00:18:03
kellancoinupvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/07/27 00:18:03
| voter | kellancoin |
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24527920/Trx d204e0d42b38b50b2859cefb33256101385db571 |
View Raw JSON Data
{
"trx_id": "d204e0d42b38b50b2859cefb33256101385db571",
"block": 24527920,
"trx_in_block": 40,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-27T00:18:03",
"op": [
"vote",
{
"voter": "kellancoin",
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"weight": 10000
}
]
}gaboskiupvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/07/26 13:34:24
gaboskiupvoted (100.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/07/26 13:34:24
| voter | gaboski |
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24515077/Trx 9f9fba6e9a9a876cbdf7bad78ef6b1d5d21b8dda |
View Raw JSON Data
{
"trx_id": "9f9fba6e9a9a876cbdf7bad78ef6b1d5d21b8dda",
"block": 24515077,
"trx_in_block": 46,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-26T13:34:24",
"op": [
"vote",
{
"voter": "gaboski",
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"weight": 10000
}
]
}mabdullah22followed @steemsports2018/07/26 12:11:00
mabdullah22followed @steemsports
2018/07/26 12:11:00
| required auths | [] |
| required posting auths | ["mabdullah22"] |
| id | follow |
| json | ["follow",{"follower":"mabdullah22","following":"steemsports","what":["blog"]}] |
| Transaction Info | Block #24513413/Trx de254ceec9cc3905e65a60d647d59a4b81ef056d |
View Raw JSON Data
{
"trx_id": "de254ceec9cc3905e65a60d647d59a4b81ef056d",
"block": 24513413,
"trx_in_block": 55,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-26T12:11:00",
"op": [
"custom_json",
{
"required_auths": [],
"required_posting_auths": [
"mabdullah22"
],
"id": "follow",
"json": "[\"follow\",{\"follower\":\"mabdullah22\",\"following\":\"steemsports\",\"what\":[\"blog\"]}]"
}
]
}mabdullah22followed @minnowbooster2018/07/26 12:04:06
mabdullah22followed @minnowbooster
2018/07/26 12:04:06
| required auths | [] |
| required posting auths | ["mabdullah22"] |
| id | follow |
| json | ["follow",{"follower":"mabdullah22","following":"minnowbooster","what":["blog"]}] |
| Transaction Info | Block #24513276/Trx eec9b3a32a8c878cfa9c30800864be980ffc73a8 |
View Raw JSON Data
{
"trx_id": "eec9b3a32a8c878cfa9c30800864be980ffc73a8",
"block": 24513276,
"trx_in_block": 9,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-26T12:04:06",
"op": [
"custom_json",
{
"required_auths": [],
"required_posting_auths": [
"mabdullah22"
],
"id": "follow",
"json": "[\"follow\",{\"follower\":\"mabdullah22\",\"following\":\"minnowbooster\",\"what\":[\"blog\"]}]"
}
]
}2018/07/26 11:45:15
2018/07/26 11:45:15
| voter | mabdullah22 |
| author | mahdiyari |
| permlink | dblog-io-decentralized-blogging-platform-frontend-and-backend-improvement |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24512900/Trx 180b3c8e982184fe7dafbbb7ea506dafff9b105c |
View Raw JSON Data
{
"trx_id": "180b3c8e982184fe7dafbbb7ea506dafff9b105c",
"block": 24512900,
"trx_in_block": 23,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-26T11:45:15",
"op": [
"vote",
{
"voter": "mabdullah22",
"author": "mahdiyari",
"permlink": "dblog-io-decentralized-blogging-platform-frontend-and-backend-improvement",
"weight": 10000
}
]
}mabdullah22upvoted (100.00%) @vlemon / daily-crypto-calendar-july-26th2018/07/26 11:34:30
mabdullah22upvoted (100.00%) @vlemon / daily-crypto-calendar-july-26th
2018/07/26 11:34:30
| voter | mabdullah22 |
| author | vlemon |
| permlink | daily-crypto-calendar-july-26th |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24512686/Trx bdb2ad2c2f552ff10a63853aeff6924d55b57196 |
View Raw JSON Data
{
"trx_id": "bdb2ad2c2f552ff10a63853aeff6924d55b57196",
"block": 24512686,
"trx_in_block": 22,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-26T11:34:30",
"op": [
"vote",
{
"voter": "mabdullah22",
"author": "vlemon",
"permlink": "daily-crypto-calendar-july-26th",
"weight": 10000
}
]
}2018/07/26 11:32:00
2018/07/26 11:32:00
| voter | mabdullah22 |
| author | cryptopassion |
| permlink | steem-progressing-in-the-direction-of-our-resistance-line-at-1-50usd |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24512636/Trx 27238b1b819ab6f8e47ea2638f3e8c46d8aa78af |
View Raw JSON Data
{
"trx_id": "27238b1b819ab6f8e47ea2638f3e8c46d8aa78af",
"block": 24512636,
"trx_in_block": 60,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-26T11:32:00",
"op": [
"vote",
{
"voter": "mabdullah22",
"author": "cryptopassion",
"permlink": "steem-progressing-in-the-direction-of-our-resistance-line-at-1-50usd",
"weight": 10000
}
]
}mabdullah22upvoted (100.00%) @steemit-bot / the-price-of-the-steem-and-steem-dollar-today-25-72018/07/26 11:22:39
mabdullah22upvoted (100.00%) @steemit-bot / the-price-of-the-steem-and-steem-dollar-today-25-7
2018/07/26 11:22:39
| voter | mabdullah22 |
| author | steemit-bot |
| permlink | the-price-of-the-steem-and-steem-dollar-today-25-7 |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24512449/Trx c382b42e6224ba180f28516d74d067a4299922d7 |
View Raw JSON Data
{
"trx_id": "c382b42e6224ba180f28516d74d067a4299922d7",
"block": 24512449,
"trx_in_block": 13,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-26T11:22:39",
"op": [
"vote",
{
"voter": "mabdullah22",
"author": "steemit-bot",
"permlink": "the-price-of-the-steem-and-steem-dollar-today-25-7",
"weight": 10000
}
]
}mabdullah22upvoted (100.00%) @themightyvolcano / pickleball2018/07/26 11:22:12
mabdullah22upvoted (100.00%) @themightyvolcano / pickleball
2018/07/26 11:22:12
| voter | mabdullah22 |
| author | themightyvolcano |
| permlink | pickleball |
| weight | 10000 (100.00%) |
| Transaction Info | Block #24512440/Trx 833ec0d86cfd9c868295d6b0182bbf6706c78b3d |
View Raw JSON Data
{
"trx_id": "833ec0d86cfd9c868295d6b0182bbf6706c78b3d",
"block": 24512440,
"trx_in_block": 45,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-26T11:22:12",
"op": [
"vote",
{
"voter": "mabdullah22",
"author": "themightyvolcano",
"permlink": "pickleball",
"weight": 10000
}
]
}mabdullah22updated their account properties2018/07/26 11:00:39
mabdullah22updated their account properties
2018/07/26 11:00:39
| account | mabdullah22 |
| posting | {"weight_threshold":1,"account_auths":[["steem.app",1]],"key_auths":[["STM6LCLT9whkfjYZTyB7hCUYXUhTFEyHbGkXjNowLpjQWareDxyBr",1]]} |
| memo key | STM6FBAxt6yNU1wULZpmUy4CUcn92pMRWZ5HTfFgCLJSPP9BwZ3qJ |
| json metadata | {"profile":{"profile_image":"https://cdn.steemitimages.com/DQmZTZdNU9eVrZz5FeFJKDoRWrd3a96euu8ZpB76AVsA46E/DSC_0514.jpg","name":"Muhammad Abdullah","about":"Undergrad Computer Engineering Student From Pakistan ,Interested in Hacking and Photography"}} |
| Transaction Info | Block #24512011/Trx 5214e769d01301ee560e6d874ec9c75153b653ed |
View Raw JSON Data
{
"trx_id": "5214e769d01301ee560e6d874ec9c75153b653ed",
"block": 24512011,
"trx_in_block": 26,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-26T11:00:39",
"op": [
"account_update",
{
"account": "mabdullah22",
"posting": {
"weight_threshold": 1,
"account_auths": [
[
"steem.app",
1
]
],
"key_auths": [
[
"STM6LCLT9whkfjYZTyB7hCUYXUhTFEyHbGkXjNowLpjQWareDxyBr",
1
]
]
},
"memo_key": "STM6FBAxt6yNU1wULZpmUy4CUcn92pMRWZ5HTfFgCLJSPP9BwZ3qJ",
"json_metadata": "{\"profile\":{\"profile_image\":\"https://cdn.steemitimages.com/DQmZTZdNU9eVrZz5FeFJKDoRWrd3a96euu8ZpB76AVsA46E/DSC_0514.jpg\",\"name\":\"Muhammad Abdullah\",\"about\":\"Undergrad Computer Engineering Student From Pakistan ,Interested in Hacking and Photography\"}}"
}
]
}2018/07/26 08:21:18
2018/07/26 08:21:18
| parent author | steemek |
| parent permlink | re-mabdullah22-how-i-hacked-a-crypto-exchange-bug-bounty-writeup-20180725t222128713z |
| author | mabdullah22 |
| permlink | re-steemek-re-mabdullah22-how-i-hacked-a-crypto-exchange-bug-bounty-writeup-20180726t082112529z |
| title | |
| body | To intercept you need to Install Burp CA certificates in your browser ...Look at this https://portswigger.net/burp/help/proxy_options_installingcacert After which you can browse and intercept HTTPS request ...I hope it clears... |
| json metadata | {"tags":["cryptocurrency"],"links":["https://portswigger.net/burp/help/proxy_options_installingcacert"],"app":"steemit/0.1"} |
| Transaction Info | Block #24508833/Trx d9ce032ba1c3020d0045522398f4c46c40ce5ac3 |
View Raw JSON Data
{
"trx_id": "d9ce032ba1c3020d0045522398f4c46c40ce5ac3",
"block": 24508833,
"trx_in_block": 11,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-26T08:21:18",
"op": [
"comment",
{
"parent_author": "steemek",
"parent_permlink": "re-mabdullah22-how-i-hacked-a-crypto-exchange-bug-bounty-writeup-20180725t222128713z",
"author": "mabdullah22",
"permlink": "re-steemek-re-mabdullah22-how-i-hacked-a-crypto-exchange-bug-bounty-writeup-20180726t082112529z",
"title": "",
"body": "To intercept you need to Install Burp CA certificates in your browser ...Look at this https://portswigger.net/burp/help/proxy_options_installingcacert \n\nAfter which you can browse and intercept HTTPS request ...I hope it clears...",
"json_metadata": "{\"tags\":[\"cryptocurrency\"],\"links\":[\"https://portswigger.net/burp/help/proxy_options_installingcacert\"],\"app\":\"steemit/0.1\"}"
}
]
}mabdullah22unfollowed @money-guru2018/07/26 08:14:45
mabdullah22unfollowed @money-guru
2018/07/26 08:14:45
| required auths | [] |
| required posting auths | ["mabdullah22"] |
| id | follow |
| json | ["follow",{"follower":"mabdullah22","following":"money-guru","what":[]}] |
| Transaction Info | Block #24508702/Trx 540646cd09aa7c01ab51024bf35910167f849eef |
View Raw JSON Data
{
"trx_id": "540646cd09aa7c01ab51024bf35910167f849eef",
"block": 24508702,
"trx_in_block": 16,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-26T08:14:45",
"op": [
"custom_json",
{
"required_auths": [],
"required_posting_auths": [
"mabdullah22"
],
"id": "follow",
"json": "[\"follow\",{\"follower\":\"mabdullah22\",\"following\":\"money-guru\",\"what\":[]}]"
}
]
}steemekupvoted (5.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/07/25 22:21:27
steemekupvoted (5.00%) @mabdullah22 / how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/07/25 22:21:27
| voter | steemek |
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| weight | 500 (5.00%) |
| Transaction Info | Block #24496851/Trx 6d2f0ef9d80a4f629ce0dd30587ac347e22bace4 |
View Raw JSON Data
{
"trx_id": "6d2f0ef9d80a4f629ce0dd30587ac347e22bace4",
"block": 24496851,
"trx_in_block": 36,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-25T22:21:27",
"op": [
"vote",
{
"voter": "steemek",
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"weight": 500
}
]
}2018/07/25 22:21:24
2018/07/25 22:21:24
| parent author | mabdullah22 |
| parent permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| author | steemek |
| permlink | re-mabdullah22-how-i-hacked-a-crypto-exchange-bug-bounty-writeup-20180725t222128713z |
| title | |
| body | Noob talking: How can you intercept traffic from "HTTPS" encrypted sites with Burp or any software?It's encrypted,right?? |
| json metadata | {"tags":["cryptocurrency"],"app":"steemit/0.1"} |
| Transaction Info | Block #24496850/Trx 92e4d7404581469d80d97326db508f973bf104fb |
View Raw JSON Data
{
"trx_id": "92e4d7404581469d80d97326db508f973bf104fb",
"block": 24496850,
"trx_in_block": 20,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-25T22:21:24",
"op": [
"comment",
{
"parent_author": "mabdullah22",
"parent_permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"author": "steemek",
"permlink": "re-mabdullah22-how-i-hacked-a-crypto-exchange-bug-bounty-writeup-20180725t222128713z",
"title": "",
"body": "Noob talking:\nHow can you intercept traffic from \"HTTPS\" encrypted sites with Burp or any software?It's encrypted,right??",
"json_metadata": "{\"tags\":[\"cryptocurrency\"],\"app\":\"steemit/0.1\"}"
}
]
}mabdullah22followed @theshahzada2018/07/25 22:12:06
mabdullah22followed @theshahzada
2018/07/25 22:12:06
| required auths | [] |
| required posting auths | ["mabdullah22"] |
| id | follow |
| json | ["follow",{"follower":"mabdullah22","following":"theshahzada","what":["blog"]}] |
| Transaction Info | Block #24496664/Trx 46d7cc582b4a635ee6cbf7b477df7bb48c3a0587 |
View Raw JSON Data
{
"trx_id": "46d7cc582b4a635ee6cbf7b477df7bb48c3a0587",
"block": 24496664,
"trx_in_block": 3,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-25T22:12:06",
"op": [
"custom_json",
{
"required_auths": [],
"required_posting_auths": [
"mabdullah22"
],
"id": "follow",
"json": "[\"follow\",{\"follower\":\"mabdullah22\",\"following\":\"theshahzada\",\"what\":[\"blog\"]}]"
}
]
}mabdullah22followed @moneyguruu2018/07/25 22:11:21
mabdullah22followed @moneyguruu
2018/07/25 22:11:21
| required auths | [] |
| required posting auths | ["mabdullah22"] |
| id | follow |
| json | ["follow",{"follower":"mabdullah22","following":"moneyguruu","what":["blog"]}] |
| Transaction Info | Block #24496649/Trx 56cc5c3f4074fd9924211e5d432a871d81b899ae |
View Raw JSON Data
{
"trx_id": "56cc5c3f4074fd9924211e5d432a871d81b899ae",
"block": 24496649,
"trx_in_block": 38,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-25T22:11:21",
"op": [
"custom_json",
{
"required_auths": [],
"required_posting_auths": [
"mabdullah22"
],
"id": "follow",
"json": "[\"follow\",{\"follower\":\"mabdullah22\",\"following\":\"moneyguruu\",\"what\":[\"blog\"]}]"
}
]
}mabdullah22updated their account properties2018/07/25 22:09:42
mabdullah22updated their account properties
2018/07/25 22:09:42
| account | mabdullah22 |
| memo key | STM6FBAxt6yNU1wULZpmUy4CUcn92pMRWZ5HTfFgCLJSPP9BwZ3qJ |
| json metadata | {"profile":{"profile_image":"https://cdn.steemitimages.com/DQmZTZdNU9eVrZz5FeFJKDoRWrd3a96euu8ZpB76AVsA46E/DSC_0514.jpg","name":"Muhammad Abdullah","about":"Undergrad Computer Engineering Student From Pakistan ,Interested in Hacking and Photography"}} |
| Transaction Info | Block #24496616/Trx 080704d913e4068bd1d3415ddef77facd35c17cf |
View Raw JSON Data
{
"trx_id": "080704d913e4068bd1d3415ddef77facd35c17cf",
"block": 24496616,
"trx_in_block": 7,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-25T22:09:42",
"op": [
"account_update",
{
"account": "mabdullah22",
"memo_key": "STM6FBAxt6yNU1wULZpmUy4CUcn92pMRWZ5HTfFgCLJSPP9BwZ3qJ",
"json_metadata": "{\"profile\":{\"profile_image\":\"https://cdn.steemitimages.com/DQmZTZdNU9eVrZz5FeFJKDoRWrd3a96euu8ZpB76AVsA46E/DSC_0514.jpg\",\"name\":\"Muhammad Abdullah\",\"about\":\"Undergrad Computer Engineering Student From Pakistan ,Interested in Hacking and Photography\"}}"
}
]
}mabdullah22published a new post: how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/07/25 21:45:03
mabdullah22published a new post: how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/07/25 21:45:03
| parent author | |
| parent permlink | cryptocurrency |
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| title | How I hacked a Crypto Exchange (Bug Bounty Writeup) |
| body | @@ -1697,16 +1697,19 @@ ypass %0A%0A +## IDOR in |
| json metadata | {"tags":["cryptocurrency","exchange","security","infosec","bugbounty"],"image":["https://cdn.steemitimages.com/DQmf26JK6sQmu7a8yQxLKxSnaTXF4sfuQpQnkrZPeFdVFrz/reset%20request.PNG","https://cdn.steemitimages.com/DQmfNsM2p57yL8WbvERod1wh3ovYstHbpcH99ZkkGeVVpbA/Minionshappyyay.gif","https://cdn.steemitimages.com/DQmdx1sZHS2t1xPwrZ7CRUhrjBQHwBKAwKBTvLBhPtNzVFJ/2fa%20request.PNG","https://cdn.steemitimages.com/DQmSAFa2A12DnKfzXhA6aTZxwHZhzKhxGprgFFhvVLae1M6/2fa%20response.PNG"],"links":["https://www.owasp.org/index.php/Top_10_2010-A4-Insecure_Direct_Object_References","http://xyz.exchange/#/reset_password/cet6YhGBFVD89jnuOiVMwfdr4mcsaeEwk2OimSc0LtVg"],"app":"steemit/0.1","format":"markdown"} |
| Transaction Info | Block #24496123/Trx ea9abb0bd53fc32ab66df1447d694b2a4004ecfd |
View Raw JSON Data
{
"trx_id": "ea9abb0bd53fc32ab66df1447d694b2a4004ecfd",
"block": 24496123,
"trx_in_block": 18,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-25T21:45:03",
"op": [
"comment",
{
"parent_author": "",
"parent_permlink": "cryptocurrency",
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"title": "How I hacked a Crypto Exchange (Bug Bounty Writeup)",
"body": "@@ -1697,16 +1697,19 @@\n ypass %0A%0A\n+## \n IDOR in \n",
"json_metadata": "{\"tags\":[\"cryptocurrency\",\"exchange\",\"security\",\"infosec\",\"bugbounty\"],\"image\":[\"https://cdn.steemitimages.com/DQmf26JK6sQmu7a8yQxLKxSnaTXF4sfuQpQnkrZPeFdVFrz/reset%20request.PNG\",\"https://cdn.steemitimages.com/DQmfNsM2p57yL8WbvERod1wh3ovYstHbpcH99ZkkGeVVpbA/Minionshappyyay.gif\",\"https://cdn.steemitimages.com/DQmdx1sZHS2t1xPwrZ7CRUhrjBQHwBKAwKBTvLBhPtNzVFJ/2fa%20request.PNG\",\"https://cdn.steemitimages.com/DQmSAFa2A12DnKfzXhA6aTZxwHZhzKhxGprgFFhvVLae1M6/2fa%20response.PNG\"],\"links\":[\"https://www.owasp.org/index.php/Top_10_2010-A4-Insecure_Direct_Object_References\",\"http://xyz.exchange/#/reset_password/cet6YhGBFVD89jnuOiVMwfdr4mcsaeEwk2OimSc0LtVg\"],\"app\":\"steemit/0.1\",\"format\":\"markdown\"}"
}
]
}mabdullah22published a new post: how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/07/25 21:42:39
mabdullah22published a new post: how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/07/25 21:42:39
| parent author | |
| parent permlink | cryptocurrency |
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| title | How I hacked a Crypto Exchange (Bug Bounty Writeup) |
| body | @@ -668,16 +668,18 @@ IDOR.%0A%0A +# Descript @@ -1495,16 +1495,42 @@ ences%0A%0A%0A +# Testing + Exploitation : %0AIDOR!! @@ -3461,16 +3461,18 @@ ion.%0A%0A%0A%0A +# Take Awa @@ -3612,16 +3612,18 @@ nses.%0A%0A%0A +# Time-lin |
| json metadata | {"tags":["cryptocurrency","exchange","security","infosec","bugbounty"],"image":["https://cdn.steemitimages.com/DQmf26JK6sQmu7a8yQxLKxSnaTXF4sfuQpQnkrZPeFdVFrz/reset%20request.PNG","https://cdn.steemitimages.com/DQmfNsM2p57yL8WbvERod1wh3ovYstHbpcH99ZkkGeVVpbA/Minionshappyyay.gif","https://cdn.steemitimages.com/DQmdx1sZHS2t1xPwrZ7CRUhrjBQHwBKAwKBTvLBhPtNzVFJ/2fa%20request.PNG","https://cdn.steemitimages.com/DQmSAFa2A12DnKfzXhA6aTZxwHZhzKhxGprgFFhvVLae1M6/2fa%20response.PNG"],"links":["https://www.owasp.org/index.php/Top_10_2010-A4-Insecure_Direct_Object_References","http://xyz.exchange/#/reset_password/cet6YhGBFVD89jnuOiVMwfdr4mcsaeEwk2OimSc0LtVg"],"app":"steemit/0.1","format":"markdown"} |
| Transaction Info | Block #24496075/Trx cd7953171682f537210a363a6b2ccf5afdba812e |
View Raw JSON Data
{
"trx_id": "cd7953171682f537210a363a6b2ccf5afdba812e",
"block": 24496075,
"trx_in_block": 39,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-25T21:42:39",
"op": [
"comment",
{
"parent_author": "",
"parent_permlink": "cryptocurrency",
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"title": "How I hacked a Crypto Exchange (Bug Bounty Writeup)",
"body": "@@ -668,16 +668,18 @@\n IDOR.%0A%0A\n+# \n Descript\n@@ -1495,16 +1495,42 @@\n ences%0A%0A%0A\n+# Testing + Exploitation :\n %0AIDOR!! \n@@ -3461,16 +3461,18 @@\n ion.%0A%0A%0A%0A\n+# \n Take Awa\n@@ -3612,16 +3612,18 @@\n nses.%0A%0A%0A\n+# \n Time-lin\n",
"json_metadata": "{\"tags\":[\"cryptocurrency\",\"exchange\",\"security\",\"infosec\",\"bugbounty\"],\"image\":[\"https://cdn.steemitimages.com/DQmf26JK6sQmu7a8yQxLKxSnaTXF4sfuQpQnkrZPeFdVFrz/reset%20request.PNG\",\"https://cdn.steemitimages.com/DQmfNsM2p57yL8WbvERod1wh3ovYstHbpcH99ZkkGeVVpbA/Minionshappyyay.gif\",\"https://cdn.steemitimages.com/DQmdx1sZHS2t1xPwrZ7CRUhrjBQHwBKAwKBTvLBhPtNzVFJ/2fa%20request.PNG\",\"https://cdn.steemitimages.com/DQmSAFa2A12DnKfzXhA6aTZxwHZhzKhxGprgFFhvVLae1M6/2fa%20response.PNG\"],\"links\":[\"https://www.owasp.org/index.php/Top_10_2010-A4-Insecure_Direct_Object_References\",\"http://xyz.exchange/#/reset_password/cet6YhGBFVD89jnuOiVMwfdr4mcsaeEwk2OimSc0LtVg\"],\"app\":\"steemit/0.1\",\"format\":\"markdown\"}"
}
]
}mabdullah22published a new post: how-i-hacked-a-crypto-exchange-bug-bounty-writeup2018/07/25 21:38:24
mabdullah22published a new post: how-i-hacked-a-crypto-exchange-bug-bounty-writeup
2018/07/25 21:38:24
| parent author | |
| parent permlink | cryptocurrency |
| author | mabdullah22 |
| permlink | how-i-hacked-a-crypto-exchange-bug-bounty-writeup |
| title | How I hacked a Crypto Exchange (Bug Bounty Writeup) |
| body | Hi This is my first write-up on Steem and also a Info-Sec writeup after a long time. The story starts when My 6th semester ended and I got some time to hunt. In summer break you have HELL of a time. So I was looking to hunt some website, tied of Duplicates on Hackerone. I came across a Crypto Exchange while surfing google.I won’t be taking the Exchange name here let's say it as xyz.exchange. So I signed up for the exchange and started testing it. The exchange was highly vulnerable, I was surprised to see that an exchange having volume in thousand of BTC is vulnerable to these type of Vulnerabilities. The bug which helped me to hack the whole exchange was IDOR. Description: Insecure Direct Object References occur when an application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers can bypass authorization and access resources in the system directly, for example, database records or files. Insecure Direct Object References allow attackers to bypass authorization and access resources directly by modifying the value of a parameter used to directly point to an object. Such resources can be database entries belonging to other users, files in the system, and more. This is caused by the fact that the application takes user-supplied input and uses it to retrieve an object without performing sufficient authorization checks. Reference: https://www.owasp.org/index.php/Top_10_2010-A4-Insecure_Direct_Object_References IDOR!! I love IDORs , especially when they are in Password Reset functionality. This attack basically consists of two vulnerabilities. IDOR in Password Reset + 2fa bypass IDOR in Password Reset Functionality: When I Requested a password reset link I got something like below http://xyz.exchange/#/reset_password/cet6YhGBFVD89jnuOiVMwfdr4mcsaeEwk2OimSc0LtVg I thought that the exchange is using some kind of token implementation here. But I was wrong when I intercepted my Request in Burp. It was a simple POST request being made at /api/reset_password  This request had an id parameter. Every user is assigned an id in the system. The id was incrementing id. From a Hacker perspective, I first thing that came into my mind was what happens if I change this id. And to my surprise, it was vulnerable to IDOR. I made two accounts and tested it and it WORKED!!! I was like…  Now comes the second part. Taking over the full account is not possible without correct 2fa token as its required upon login. For confirming the 2fa token the following request was being made.  Code as the 2fa token. I set the burp to show its response. The response was as follows.  So the trick was to just set the response to true as you will get access to the account even token as “123456”. Later I found the Admin’s Email and his corresponding account Id via using IDOR in their Ticket System. But I didn’t exploited it as COO didn’t give me the permission. Take Aways: ~ Burp is your Ultimate Friend Always keep it on and Look at every Request being Made. ~ Never Forget to Play With Request Responses. Time-line: Getting this bug to Authorities was another story Which I will share some other time. June. 16, 2018 → Initial Report Sent NO RESPONSE June. 30, 2018 → Mail for Update NO RESPONSE July. 6, 2018 → Reported Via Telegram group of Exchange July. 6, 2018 → Triaged July. 7, 2018 → Fixed July. 7, 2018 → Bounty awarded |
| json metadata | {"tags":["cryptocurrency"],"image":["https://cdn.steemitimages.com/DQmf26JK6sQmu7a8yQxLKxSnaTXF4sfuQpQnkrZPeFdVFrz/reset%20request.PNG","https://cdn.steemitimages.com/DQmfNsM2p57yL8WbvERod1wh3ovYstHbpcH99ZkkGeVVpbA/Minionshappyyay.gif","https://cdn.steemitimages.com/DQmdx1sZHS2t1xPwrZ7CRUhrjBQHwBKAwKBTvLBhPtNzVFJ/2fa%20request.PNG","https://cdn.steemitimages.com/DQmSAFa2A12DnKfzXhA6aTZxwHZhzKhxGprgFFhvVLae1M6/2fa%20response.PNG"],"links":["https://www.owasp.org/index.php/Top_10_2010-A4-Insecure_Direct_Object_References","http://xyz.exchange/#/reset_password/cet6YhGBFVD89jnuOiVMwfdr4mcsaeEwk2OimSc0LtVg"],"app":"steemit/0.1","format":"markdown"} |
| Transaction Info | Block #24495990/Trx d23a094d7c59246c302f3e9e198b762fdd81b6b9 |
View Raw JSON Data
{
"trx_id": "d23a094d7c59246c302f3e9e198b762fdd81b6b9",
"block": 24495990,
"trx_in_block": 26,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-25T21:38:24",
"op": [
"comment",
{
"parent_author": "",
"parent_permlink": "cryptocurrency",
"author": "mabdullah22",
"permlink": "how-i-hacked-a-crypto-exchange-bug-bounty-writeup",
"title": "How I hacked a Crypto Exchange (Bug Bounty Writeup)",
"body": "Hi\nThis is my first write-up on Steem and also a Info-Sec writeup after a long time. The story starts when My 6th semester ended and I got some time to hunt. In summer break you have HELL of a time. So I was looking to hunt some website, tied of Duplicates on Hackerone. I came across a Crypto Exchange while surfing google.I won’t be taking the Exchange name here let's say it as xyz.exchange. \n\nSo I signed up for the exchange and started testing it. The exchange was highly vulnerable, I was surprised to see that an exchange having volume in thousand of BTC is vulnerable to these type of Vulnerabilities. \n\nThe bug which helped me to hack the whole exchange was IDOR.\n\nDescription:\nInsecure Direct Object References occur when an application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers can bypass authorization and access resources in the system directly, for example, database records or files. \nInsecure Direct Object References allow attackers to bypass authorization and access resources directly by modifying the value of a parameter used to directly point to an object. Such resources can be database entries belonging to other users, files in the system, and more. This is caused by the fact that the application takes user-supplied input and uses it to retrieve an object without performing sufficient authorization checks. \n\nReference: https://www.owasp.org/index.php/Top_10_2010-A4-Insecure_Direct_Object_References\n\n\n\nIDOR!! I love IDORs , especially when they are in Password Reset functionality.\n\nThis attack basically consists of two vulnerabilities.\n\nIDOR in Password Reset + 2fa bypass \n\nIDOR in Password Reset Functionality:\n\nWhen I Requested a password reset link I got something like below\n\nhttp://xyz.exchange/#/reset_password/cet6YhGBFVD89jnuOiVMwfdr4mcsaeEwk2OimSc0LtVg\n\n\nI thought that the exchange is using some kind of token implementation here. But I was wrong when I intercepted my Request in Burp. It was a simple POST request being made at /api/reset_password\n\n\n\n\n\n\n\nThis request had an id parameter. Every user is assigned an id in the system. The id was incrementing id. From a Hacker perspective, I first thing that came into my mind was what happens if I change this id. And to my surprise, it was vulnerable to IDOR.\nI made two accounts and tested it and it WORKED!!!\n\nI was like…\n\n\n\n\nNow comes the second part. Taking over the full account is not possible without correct 2fa token as its required upon login.\n\nFor confirming the 2fa token the following request was being made.\n\n\n\n\n\nCode as the 2fa token. I set the burp to show its response. The response was as follows.\n\n\n\n\n\nSo the trick was to just set the response to true as you will get access to the account even token as “123456”.\n\nLater I found the Admin’s Email and his corresponding account Id via using IDOR in their Ticket System. But I didn’t exploited it as COO didn’t give me the permission.\n\n\n\nTake Aways:\n\n~ Burp is your Ultimate Friend Always keep it on and Look at every Request being Made.\n~ Never Forget to Play With Request Responses.\n\n\nTime-line:\nGetting this bug to Authorities was another story Which I will share some other time.\n\nJune. 16, 2018 → Initial Report Sent \n\t\t NO RESPONSE\nJune. 30, 2018 → Mail for Update\n\t NO RESPONSE\nJuly. 6, 2018 → Reported Via Telegram group of Exchange\nJuly. 6, 2018 → Triaged\nJuly. 7, 2018 → Fixed \nJuly. 7, 2018 → Bounty awarded",
"json_metadata": "{\"tags\":[\"cryptocurrency\"],\"image\":[\"https://cdn.steemitimages.com/DQmf26JK6sQmu7a8yQxLKxSnaTXF4sfuQpQnkrZPeFdVFrz/reset%20request.PNG\",\"https://cdn.steemitimages.com/DQmfNsM2p57yL8WbvERod1wh3ovYstHbpcH99ZkkGeVVpbA/Minionshappyyay.gif\",\"https://cdn.steemitimages.com/DQmdx1sZHS2t1xPwrZ7CRUhrjBQHwBKAwKBTvLBhPtNzVFJ/2fa%20request.PNG\",\"https://cdn.steemitimages.com/DQmSAFa2A12DnKfzXhA6aTZxwHZhzKhxGprgFFhvVLae1M6/2fa%20response.PNG\"],\"links\":[\"https://www.owasp.org/index.php/Top_10_2010-A4-Insecure_Direct_Object_References\",\"http://xyz.exchange/#/reset_password/cet6YhGBFVD89jnuOiVMwfdr4mcsaeEwk2OimSc0LtVg\"],\"app\":\"steemit/0.1\",\"format\":\"markdown\"}"
}
]
}mabdullah22followed @money-guru2018/07/25 21:20:06
mabdullah22followed @money-guru
2018/07/25 21:20:06
| required auths | [] |
| required posting auths | ["mabdullah22"] |
| id | follow |
| json | ["follow",{"follower":"mabdullah22","following":"money-guru","what":["blog"]}] |
| Transaction Info | Block #24495624/Trx eaaa17e28c7a7c6ec40b3b820aba339172851aa2 |
View Raw JSON Data
{
"trx_id": "eaaa17e28c7a7c6ec40b3b820aba339172851aa2",
"block": 24495624,
"trx_in_block": 19,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-25T21:20:06",
"op": [
"custom_json",
{
"required_auths": [],
"required_posting_auths": [
"mabdullah22"
],
"id": "follow",
"json": "[\"follow\",{\"follower\":\"mabdullah22\",\"following\":\"money-guru\",\"what\":[\"blog\"]}]"
}
]
}blocktradessent 0.858 STEEM to @mabdullah222018/07/25 21:16:09
blocktradessent 0.858 STEEM to @mabdullah22
2018/07/25 21:16:09
| from | blocktrades |
| to | mabdullah22 |
| amount | 0.858 STEEM |
| memo | |
| Transaction Info | Block #24495545/Trx 9bb8ef0f354895a6c8ddb6475bfb9961542387ed |
View Raw JSON Data
{
"trx_id": "9bb8ef0f354895a6c8ddb6475bfb9961542387ed",
"block": 24495545,
"trx_in_block": 26,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-25T21:16:09",
"op": [
"transfer",
{
"from": "blocktrades",
"to": "mabdullah22",
"amount": "0.858 STEEM",
"memo": ""
}
]
}blocktradescreated a new account: @mabdullah222018/07/25 21:16:09
blocktradescreated a new account: @mabdullah22
2018/07/25 21:16:09
| fee | 3.000 STEEM |
| creator | blocktrades |
| new account name | mabdullah22 |
| owner | {"weight_threshold":1,"account_auths":[],"key_auths":[["STM8jEN9rHcUDRSdaqwhbit3Z2t9jzcC9Jvsz7BELmB2oEmtkayUM",1]]} |
| active | {"weight_threshold":1,"account_auths":[],"key_auths":[["STM6gVXGHnRQLMWHS7bBTyGRJgeseVqGsaTpNbjX8goYYXF4ygaMc",1]]} |
| posting | {"weight_threshold":1,"account_auths":[],"key_auths":[["STM6LCLT9whkfjYZTyB7hCUYXUhTFEyHbGkXjNowLpjQWareDxyBr",1]]} |
| memo key | STM6FBAxt6yNU1wULZpmUy4CUcn92pMRWZ5HTfFgCLJSPP9BwZ3qJ |
| json metadata | {} |
| Transaction Info | Block #24495545/Trx 9bb8ef0f354895a6c8ddb6475bfb9961542387ed |
View Raw JSON Data
{
"trx_id": "9bb8ef0f354895a6c8ddb6475bfb9961542387ed",
"block": 24495545,
"trx_in_block": 26,
"op_in_trx": 0,
"virtual_op": 0,
"timestamp": "2018-07-25T21:16:09",
"op": [
"account_create",
{
"fee": "3.000 STEEM",
"creator": "blocktrades",
"new_account_name": "mabdullah22",
"owner": {
"weight_threshold": 1,
"account_auths": [],
"key_auths": [
[
"STM8jEN9rHcUDRSdaqwhbit3Z2t9jzcC9Jvsz7BELmB2oEmtkayUM",
1
]
]
},
"active": {
"weight_threshold": 1,
"account_auths": [],
"key_auths": [
[
"STM6gVXGHnRQLMWHS7bBTyGRJgeseVqGsaTpNbjX8goYYXF4ygaMc",
1
]
]
},
"posting": {
"weight_threshold": 1,
"account_auths": [],
"key_auths": [
[
"STM6LCLT9whkfjYZTyB7hCUYXUhTFEyHbGkXjNowLpjQWareDxyBr",
1
]
]
},
"memo_key": "STM6FBAxt6yNU1wULZpmUy4CUcn92pMRWZ5HTfFgCLJSPP9BwZ3qJ",
"json_metadata": "{}"
}
]
}Manabar
Voting Power100.00%
Downvote Power100.00%
Resource Credits100.00%
Reputation Progress0.00%
{
"voting_manabar": {
"current_mana": 9052,
"last_update_time": 1532726277
},
"downvote_manabar": {
"current_mana": 0,
"last_update_time": 1532553369
},
"rc_account": {
"account": "mabdullah22",
"rc_manabar": {
"current_mana": "8102928814",
"last_update_time": 1537887600
},
"max_rc_creation_adjustment": {
"amount": "2020748973",
"precision": 6,
"nai": "@@000000037"
},
"max_rc": "8102928814"
}
}Account Metadata
| POSTING JSON METADATA | |
| profile | {"profile_image":"https://cdn.steemitimages.com/DQmZTZdNU9eVrZz5FeFJKDoRWrd3a96euu8ZpB76AVsA46E/DSC_0514.jpg","name":"Muhammad Abdullah","about":"Undergrad Computer Engineering Student From Pakistan ,Interested in Hacking and Photography"} |
| JSON METADATA | |
| profile | {"profile_image":"https://cdn.steemitimages.com/DQmZTZdNU9eVrZz5FeFJKDoRWrd3a96euu8ZpB76AVsA46E/DSC_0514.jpg","name":"Muhammad Abdullah","about":"Undergrad Computer Engineering Student From Pakistan ,Interested in Hacking and Photography"} |
{
"posting_json_metadata": {
"profile": {
"profile_image": "https://cdn.steemitimages.com/DQmZTZdNU9eVrZz5FeFJKDoRWrd3a96euu8ZpB76AVsA46E/DSC_0514.jpg",
"name": "Muhammad Abdullah",
"about": "Undergrad Computer Engineering Student From Pakistan ,Interested in Hacking and Photography"
}
},
"json_metadata": {
"profile": {
"profile_image": "https://cdn.steemitimages.com/DQmZTZdNU9eVrZz5FeFJKDoRWrd3a96euu8ZpB76AVsA46E/DSC_0514.jpg",
"name": "Muhammad Abdullah",
"about": "Undergrad Computer Engineering Student From Pakistan ,Interested in Hacking and Photography"
}
}
}Auth Keys
Owner
Single Signature
Public Keys
STM8jEN9rHcUDRSdaqwhbit3Z2t9jzcC9Jvsz7BELmB2oEmtkayUM1/1
Active
Single Signature
Public Keys
STM6gVXGHnRQLMWHS7bBTyGRJgeseVqGsaTpNbjX8goYYXF4ygaMc1/1
Posting
Single Signature
Public Keys
STM6LCLT9whkfjYZTyB7hCUYXUhTFEyHbGkXjNowLpjQWareDxyBr1/1
App Permissions
@steem.app1/1
Memo
STM6FBAxt6yNU1wULZpmUy4CUcn92pMRWZ5HTfFgCLJSPP9BwZ3qJ
{
"owner": {
"weight_threshold": 1,
"account_auths": [],
"key_auths": [
[
"STM8jEN9rHcUDRSdaqwhbit3Z2t9jzcC9Jvsz7BELmB2oEmtkayUM",
1
]
]
},
"active": {
"weight_threshold": 1,
"account_auths": [],
"key_auths": [
[
"STM6gVXGHnRQLMWHS7bBTyGRJgeseVqGsaTpNbjX8goYYXF4ygaMc",
1
]
]
},
"posting": {
"weight_threshold": 1,
"account_auths": [
[
"steem.app",
1
]
],
"key_auths": [
[
"STM6LCLT9whkfjYZTyB7hCUYXUhTFEyHbGkXjNowLpjQWareDxyBr",
1
]
]
},
"memo": "STM6FBAxt6yNU1wULZpmUy4CUcn92pMRWZ5HTfFgCLJSPP9BwZ3qJ"
}Witness Votes
0 / 30
No active witness votes.
[]