How I got my first HOF in United Nations | 0xshahriar

Alhamdulillah !!
ٱلْحَمْدُ لِلَّٰهِ‎

This is the story about getting my first Hall Of Fame. And I got it in United Nations. 🎉🎊


After recon process, I started manual testing on each subdomains. And when I was visiting a subdomain " centre.humdata.org "  I found a search functionality. 

So, first thing came in my mind to abuse that functionality for finding vulnerabilities. As far as I know, these search boxes can be vulnerable to 3/4 things. 
  1. SQL Injection (SQLi)
  2. Cross Site Scripting (XSS)
  3. Client Side Template Injection (CSTI)
  4. Server Side Template Injection (SSTI)
So, I put my magic payload to find these three vulnerabilities with just a single hit.


Here, 
  • ' ----> is for testing SQL Injection
  • "><svg/onload=prompt(5);> ----> is for testing Cross Site Scripting vulnerability.
  • {{7*7}} ----> is for testing SSTI & CSTI.
And I got an popup. 🥳 Simplest XSS that lead me towards Hall Of Frame in United Nations. 

After reporting the vulnerability they triaged that and after almost one month they fixed that vulnerability and added my name in the United Nations Information Security Hall Of Frame.

📝 Reported at : January 14, 2022
👨‍🔧 Fixed at : February 8, 2022


I am really happy to work with United Nations and secure them. 

You can check the POC video from here ,


./keep_hacking_the_world 🥳🎊🎉🐞
A maladaptive daydreamer who is interested in cyber security & ethical hacking. I love connecting with different peoples around the whole world & love to play games & sleep 💤

Post a Comment