Open in app

Sign In

Write

Sign In

Caesar Evan Santoso
Caesar Evan Santoso

257 Followers

Home

About

Nov 10, 2022

Google VRP (Acquisitions) — [Insecure Direct Object Reference] 2nd

Hi All!, Yuuppp…It’s me again! XD. As the title suggests, I will share how I found the [Insecure Direct Object Reference] vulnerability in one of Google’s acquisitions (https://www.appsheet.com/). Description AppSheet is an application that provides a no-code development platform for application software, which allows users to create mobile, tablet, and web…

Google Vrp

3 min read

Google VRP (Acquisitions) — [Insecure Direct Object Reference] 2nd
Google VRP (Acquisitions) — [Insecure Direct Object Reference] 2nd
Google Vrp

3 min read


Oct 20, 2022

Google VRP — [Insecure Direct Object Reference] $3133.70

Hi All!!!, Yes… it’s me. As usual I want to give a story about how I find IDOR [Insecure Direct Object Reference] vulnerability on one of Google’s subdomains (https://datastudio.google.com/) Description Google Data Studio is a tools for displaying data to make it easier to read. So, you can determine a website…

Google Vrp

4 min read

Google VRP — [Insecure Direct Object Reference] $3133.70
Google VRP — [Insecure Direct Object Reference] $3133.70
Google Vrp

4 min read


Jul 20, 2022

From Stack Trace Laravel Leads to Privilege Escalation [Admin]

Hi!, In this Article I will only tell a little about the findings that I think are interesting to be used as stories on my medium.com xD Note : I found this attack on one of the Vendors and of course I will censor :) Description Stack Trace Laravel : For…

Penetration Testing

4 min read

From Stack Trace Laravel Leads to Privilege Escalation [Admin]
From Stack Trace Laravel Leads to Privilege Escalation [Admin]
Penetration Testing

4 min read


Jul 6, 2022

How I Get Pre-Auth Remote Code Execution (CVE-2021–42237) on One of the Vendors.

Hi!!!, In this Article I would like to tell you a little about how I accidentally discovered the “Pre-Auth Remote Code Execution (CVE-2021–42237)” Attack on one of the Vendors affected by this attack. Note : I will Censor any Vendor affected by this attack. Description Sitecore XP 7.5 Initial Release to…

Sitecore

4 min read

How I Get Pre-Auth Remote Code Execution (CVE-2021–42237) on One of the Vendors.
How I Get Pre-Auth Remote Code Execution (CVE-2021–42237) on One of the Vendors.
Sitecore

4 min read


Apr 9, 2022

The Journey to get “SQL Injection” at BluePay (BLUE Indonesia BluePay) — 2019

Hello, In this article i want to share my experience getting SQL Injection on BluePay (BLUE Indonesia BluePay), I found this vulnerability in 2019 when I was still a Vocational High School and this machine was very popular in my school, and that’s when I tried do Pentest on this…

Sql Injection

3 min read

The Journey to get “SQL Injection” at BluePay (BLUE Indonesia BluePay) — 2019
The Journey to get “SQL Injection” at BluePay (BLUE Indonesia BluePay) — 2019
Sql Injection

3 min read


Jan 18, 2022

How I Get ZeroDay Attack Unrestricted File Upload leads to RCE on one of the Vendors.

Hello, In this article I want to tell you a little about how I accidentally discovered the Unrestricted File Upload attack leads to Remote Code Execution on one of the vendors affected by this attack… Little Story Previously, I really didn’t know that those affected by the vulnerability that I found were…

Unrestricted File Upload

4 min read

How I Get ZeroDay Attack UFU leads to RCE on one of the Vendors.
How I Get ZeroDay Attack UFU leads to RCE on one of the Vendors.
Unrestricted File Upload

4 min read


Aug 27, 2021

SSRF External Service Interaction for Find Real IP CloudFlare and Leads to SQL Injection

Hello, here I just want to tell about my experience finding a real IP using CloudFlare through “SSRF External Interaction” and getting a form login for Admin and there is a SQL Injection bug. Little Story Previously I had also found SQLi vulnerabilities on this website but this time it felt a…

Bypass

4 min read

SSRF External Service Interaction for Find Real IP CloudFlare and Leads to SQL Injection
SSRF External Service Interaction for Find Real IP CloudFlare and Leads to SQL Injection
Bypass

4 min read


Mar 1, 2021

Bypass WAF 500 Unauthorized Access! to Reflected XSS (Cross Site Scripting)- Developer BCA

Hello, here I just want to share my experience regarding finding the XSS (Cross site scripting) bug at one of the banks in Indonesia, namely BCA (Bank Central Asia). Little Story I previously got this URL from 17 May 2019 and it comes from an email from Bank BCA, namely “Developer BCA”

Bug Bounty

3 min read

Bypass WAF 500 Unauthorized Access! to Reflected XSS (Cross Site Scripting)- Developer BCA
Bypass WAF 500 Unauthorized Access! to Reflected XSS (Cross Site Scripting)- Developer BCA
Bug Bounty

3 min read


Dec 6, 2020

Found a simple “Price Parameter Tampering” on IT Bootcamp (Indonesia)

Hello, here I just want to give a little story about the finding of the bug “Price Parameter Tampering” on one of the IT Bootcamp websites in Indonesia. Summary The Parameter tampering attack relies on the manipulation of parameters changed by the user so as to change application information like user…

Parameter Tampering

3 min read

Found a simple “Price Parameter Tampering” on IT Bootcamp (Indonesia)
Found a simple “Price Parameter Tampering” on IT Bootcamp (Indonesia)
Parameter Tampering

3 min read


Oct 2, 2020

Full Path Disclosure at Digital Payments Indonesia

Bismillah. Assalamualaikum wr wb, teman teman ^-^)/ Disini saya hanya ingin membagikan pengalaman Berburu Bug saya pada salah satu website Pembayaran Digital Indonesia, Sebelumnya terima kasih banyak kepada pak Zul Amri yang sudah memforward Laporan saya ke Team dari website tersebut. Tentang Full Path Disclosure : Kerentanan Full Path Disclosure (FPD)…

Bug Bounty

3 min read

Full Path Disclosure at Digital Payments Indonesia
Full Path Disclosure at Digital Payments Indonesia
Bug Bounty

3 min read

Caesar Evan Santoso

Caesar Evan Santoso

257 Followers

No One Knows Who I Am

Following
  • Muhamad Hidayat

    Muhamad Hidayat

  • Mike Takahashi

    Mike Takahashi

  • Jefferson Gonzales (Gonz)

    Jefferson Gonzales (Gonz)

  • Dhamotharan

    Dhamotharan

  • Rtwo Gatelie

    Rtwo Gatelie

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech