<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Bug-Bounty on krash.dev</title><link>https://krash.dev/tags/bug-bounty/</link><description>Recent content in Bug-Bounty on krash.dev</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 14 Aug 2026 08:29:09 +0530</lastBuildDate><atom:link href="https://krash.dev/tags/bug-bounty/rss.xml" rel="self" type="application/rss+xml"/><item><title>Bug Bounty Summit CTF Writeup</title><link>https://krash.dev/posts/bug-bounty-summit-ctf-writeup/</link><pubDate>Mon, 02 Nov 2020 00:00:00 +0000</pubDate><guid>https://krash.dev/posts/bug-bounty-summit-ctf-writeup/</guid><description>&lt;p&gt;&lt;em&gt;The CTF is live on Hacker101 as Grayhatcon CTF – &lt;a href="https://ctf.hacker101.com/ctf" target="_blank" rel="noopener noreferrer"&gt;Hacker101 CTF&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The CTF was built upon real vulnerabilities found during bug bounties. It had four flags – 250 points each.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;strong&gt;Objective&lt;/strong&gt; - Hackerone&amp;rsquo;s Username and Password database has been leaked and put on an auction. Our task was to delete the auction listing before anyone buys it.&lt;/p&gt;
&lt;/blockquote&gt;&lt;p&gt;We were given an IP, which resolved to a web application. On performing some basic information gathering, I found out some stuff.&lt;/p&gt;</description></item></channel></rss>