In the Name of Allah
Hello mates. I’m YoungVanda and this is my first write up. I hope this write up would be useful for you. 😊
Let’sssssssssssssssssss Gooooooooooooooooooo 🔥🔥🧨🧨(Just Vibing 😂)
Since I just started hunting I decided to go for a VDP program. After over 10 duplicates, I got my first bug which was a Reflected XSS (In another write up I’ll tell you how) and this is my second bug which triaged as critical.
The night before I was working on a simple tool to scan/monitor my assets on a regular basis with the help of passive providers and, at the end ,I added notify(tool) to my code in order to notify me if any new subdomain has been found. So I finished with writing the tool and after that I watched anime for an hour ( a bit of dopamine 🐱👤) , reading book and went to sleep.
The next day everything was normal no sign of interesting subdomains, but I was happy because my tool was working fine (I’m not a programmer🐱👓).
I went to the gym and came back, took a shower and etc and finally opening my laptop and I saw a new subdomain alert on my discord :)
I put the subdomain on my search bar and I wished I could find a XSS 😂 after 30 minutes, my internet connection was so bad, the subdomain finally has been loaded and I said damn It’s an admin panel, what should I do now?
I was disappointed and wanted to close the tab, but I said just try admin:admin, if didn’t work close it.
You know what??? It worked! I put admin:admin, it asked me for a new password and entering the new password and now I had access to one of the most juiceful admin panels in the world.
Jokes aside that admin panel was really juicy I literally could do anything.
This was almost all I knew about Grafana and I explained my own approach for finding this bug ;d
If somehow you liked this write up please give me a thumbs up and see you soon.
My Twitter Account: @young_vanda_