Open in app

Sign in

Write

Sign in

Saransh Saraf aka (MR23R0)
Saransh Saraf aka (MR23R0)

692 Followers

Home

About

Sep 16

Unlocking the Power of Observation : the front door key 🔑

We are currently in the era of SaaS applications and startups. SaaS applications have become ubiquitous, serving various purposes, from sending notifications to collecting feedback. There seems to be a SaaS application for virtually every need, and startups are capitalizing on this trend For those familiar with web applications, the…

Info Sec Writeups

3 min read

Unlocking the Power of Observation : the front door key 🔑
Unlocking the Power of Observation : the front door key 🔑
Info Sec Writeups

3 min read


Jun 8

Uncovering the Secrets : The Potential of Web Archive in Bug Bounty Programs

In the last 5 years people shared alot about web archive but no one has shared the secret vulnerabilities and it’s cause till now — The Infamous WayBack Machine : According to ChatGPT, The Wayback Machine is a digital archive of the World Wide Web, maintained by the Internet Archive. It is a valuable tool that allows users to access and browse archived versions of websites as they appeared at different points in time. …

Info Sec Writeups

4 min read

Uncovering the Secrets : The Potential of Web Archive in Bug Bounty Programs
Uncovering the Secrets : The Potential of Web Archive in Bug Bounty Programs
Info Sec Writeups

4 min read


Published in

System Weakness

·Feb 12

Unlocking the Power of Observation: How Experienced Hackers Stand Out in a Sea of Amateurs

Hackers have a superpower “Observation” but it doesn’t come naturally, a hacker gains it with experience and brainstorming but as automation and third party tools are becoming influential anyone with little computer knowledge is throwing random payloads and running automation and claiming to be “Hacker/Bug bounty hunter” — Hackers need to embrace their superpower in order to become more efficient and meaningful, while doing bug bounty they have to search for weaknesses and also make sure that with their actions the application doesn’t crash.

Bug Bounty

4 min read

Unlocking the Power of Observation: How Experienced Hackers Stand Out in a Sea of Amateurs
Unlocking the Power of Observation: How Experienced Hackers Stand Out in a Sea of Amateurs
Bug Bounty

4 min read


Oct 13, 2022

Code flaws leads to Org/Admin Account Takeover

Hello Everyone, I’m Saransh Saraf and I’m back with another unique account takeover idea, so let’s just dive into it :) Let’s Start with the Application Design : The Application was only allowing one Admin/Manager per one organization, but other viewers has to login in order to view the content…

Bug Bounty

3 min read

Code flaws leads to Org/Admin Account Takeover
Code flaws leads to Org/Admin Account Takeover
Bug Bounty

3 min read


Sep 2, 2022

The Database Handover | A Dumb Mistake | Critical BUG

Hi hackers & Security Enthusiasts, I’m Saransh Saraf and this a simple bug with a critical Impact. I hope you’ll enjoy it and learn something from it. The Wakeup Call : Have you ever used these type of tools ? ShareIt Xender Inshare ShareMe If yes, then you’re gonna enjoy it, if you never…

Infosec

4 min read

The Database Handover | A Dumb Mistake | Critical BUG
The Database Handover | A Dumb Mistake | Critical BUG
Infosec

4 min read


Jun 14, 2022

The Upstox Fraud !! Cheating with Security Researchers

Hi Hackers, I’m Saransh Saraf and today I’m gonna expose upstox fraud. (Note: I’ve read the NDA of Upstox bug bounty program and it is not against the policy) Scenario: Suppose You’ve found a bug in upstox and you’re gonna report it. Few Months ago when everyone was hunting on…

Information Security

4 min read

The Upstox Fraud !! Cheating with Security Researchers
The Upstox Fraud !! Cheating with Security Researchers
Information Security

4 min read


Jun 3, 2022

How it Started and How it is going (Full Path for Beginners)

Hi Hacking Aspirants, I am Saransh Saraf and this is my story (some_part), which will help you to become a good hacker and get a job without investing 1 Rupees. It all stared with One freaking challenge, I hope you got here with the same reason. Before we begin I…

Info Sec Writeups

4 min read

How it Started and How it is going (Full Path for Beginners)
How it Started and How it is going (Full Path for Beginners)
Info Sec Writeups

4 min read


Apr 15, 2022

Crazy Simple Insecure Design & 300$ Bounty!

Hi guys, I’m Saransh Saraf, An Indian Bug Bounty hunter & Security Researcher (I’ve also done LAMP Stack Development)and this will be a series of Logical Bugs….👾 before we explore this I want little help, If you get rewards or HoF from this give some credit 😼 You’ll get my social links at the end of this article. — Few months ago I’ve found an article of IP Grabber Bug which is also known as “pixel that steals data” here you can learn basics about this pixel data stealer bug..

Infosec

3 min read

Crazy Simple Insecure Design & 300$ Bounty!
Crazy Simple Insecure Design & 300$ Bounty!
Infosec

3 min read


Feb 7, 2022

How Google [ Security Team ] cheated ME!

Timeline: bug reported : Dec 23, 2021 04:11PM Marked as Intended behavior : Dec 23, 2021 06:25PM Cross checked : Feb 07, 2022 12:47 AM Hello fellow hackers, I’m Saransh Saraf an Indian bug bounty hunter I claimed google, give the appropriate bounty. Don’t cheat with bug bounty hunters who…

Bugbounty Writeup

3 min read

How Google [ Security Team ] cheated ME!
How Google [ Security Team ] cheated ME!
Bugbounty Writeup

3 min read


Feb 5, 2022

I Hacked Every Single Staff Account on AirIndia within 1.5 Minutes :)

Hello Beautiful creative people, hope you’re doing great. This is the continuation of “The Password Bypass Series” So first of all let me clear a point, there will be some lines which you may don’t like so please don’t take it personal. As my daily routine, I was at my…

Bugbounty Writeup

4 min read

I Hacked Every Single Staff Account on AirIndia within 1.5 Minutes :)
I Hacked Every Single Staff Account on AirIndia within 1.5 Minutes :)
Bugbounty Writeup

4 min read

Saransh Saraf aka (MR23R0)

Saransh Saraf aka (MR23R0)

692 Followers

Writer of all kind, but mainly philosophy and cybersecurity mixed with physics concepts

Following
  • Joe Procopio

    Joe Procopio

  • Petrica Leuca

    Petrica Leuca

  • David Merian

    David Merian

  • Roberto

    Roberto

  • Harsh Jaiswal

    Harsh Jaiswal

See all (68)

Help

Status

About

Careers

Blog

Privacy

Terms

Text to speech

Teams