Tag: bugbounty
From Staging to Full Admin Control In Prod: A Breakdown of Critical Authentication Flaws
In this blog, I explore a real-world case of an Admin Panel Takeover caused by broken authentication and insecure configurations. By exploiting a misconfigured JWT token from a sta…
AI Hijack: How I Took Control of an AI Assistant
A simple API key leak led to the complete takeover of an AI assistant in production. Allowing to change AI's Instructions.
Finding Hidden Threats: How I Found Leaked AWS Credentials in an Android App API Using DAST
Found a critical vulnerability involving leaked AWS credentials within an Android App API during a bug bounty hunt. by utilizing Dynamic Application Security Testing (DAST) and the…
How I Manipulated My Rank on the Bugcrowd Platform
In recent years, Bug Bounties have gained significant popularity as a growing number of companies rely on crowdsourcing platforms to identify vulnerabilities within their systems. …
Hacking 100k+ Loyalty Programs for Fun and Profit!
This blog post is about how a hacker could have Hacked 100k+ Loyalty Programs to get free points & redeem them for free stuff or coupons.
Hacking Subscription Plans for free service.
The blog post describes how I was able to bypass subscription plans to get access to paid services for free.
Using Inspect Element to Bypass Security restrictions | Bug Bounty POC
Hey guys so this blog post is how I was able to Bypass Security restrictions by using inspect element and use Paid Features.
Microsoft Apache Solr RCE Velocity Template | Bug Bounty POC
Hey guys so this blog post is about RCE issue reported to Microsoft bug bounty program, Remote Code execution issue existed in microsoft.com subdomain running Apache Solr.
Exploiting Insecure Firebase Database!
this blog post is about Exploiting Insecure Firebase Databases, due to Improper set security rules one can write data to the database in certain conditions here’s a Short POC tutor…
Hacking a Company Through help desk - Ticket Trick | Bug Bounty POC
This Blog is about how i found & used Ticket Trick issue to Hack a Comapnies Help Center and access other users support tickets
Hunting Insecure Direct Object Reference Vulnerabilities for Fun and Profit (PART-1)
This is my first Blog post and i am starting with IDOR Vulnerability. In this Post you will know about many endpoints to test IDOR vulnerability! Hope you will like it.
My Guide to Basic Recon? | Bug Bounties + Recon | Amazing Love story.
The Post describe basic steps i follow before starting actual hunt for bugs in a bug bounty program, how i map out the target and which tools to use.









