Be Patient and Keep it Simple, The Bug is There
Two simple but high-impact findings, and the lessons that led me to them.
Two simple but high-impact findings, and the lessons that led me to them.
Crawling a target I thought I knew — with Katana, hakrawler, waybackurls, and unfurl — surfaced a hidden /HelpApi/ endpoint and an IDOR leaking users' PII.
A reality check on bug bounty and the myth of easy money.
A field guide to web cache attacks — from CP-DoS tricks (oversize headers, meta characters, method override, unkeyed ports, redirect DoS) to poisoning with XSS payloads and web cache deception via path confusion.
A Broken Access Control bug on a chess platform, via request interception and cookie swapping.
Why JavaScript files are a goldmine for bug hunters — the tools (JSleak, JSecret, jsluice), the workflow, and the resources I use to dig secrets, endpoints, and client-side bugs out of JS.
A forgotten subdomain, a Shodan dork, and a single PUT request — how one overlooked endpoint led to an information disclosure and then an IDOR into users' video session data.