Web-Security

6 posts
2025

Be Patient and Keep it Simple, The Bug is There

Good Day! I hope you are doing well. Long time not writing anything… right? Well I am back again with two finding I have discoverd recently …
Read more
2024

Hunting for Hidden API Endpoints Using Katana and Hakrawler

Good day! I hope you’re doing well. In bug bounty, never say: “This idea is silly to try; the result will be nothing.” Bug …
Read more

Don't Trust the Cache: Exposing Web Cache Poisoning and Deception Vulnerabilities

Good day! I hope you’re doing well. I’ve been studying web cache vulnerabilities, so here’s a shortcut through all the …
Read more

Click, Intercept, Hack: Checkmate on Access Control Vulnerability

Good Day! I hope you are doing well. Today, I am going to share a Broken Access Control (BAC) bug that I found a while ago in one of the …
Read more

Bugs & JS: A Closer Look at JavaScript for Successful Bug Hunting

Good Day! Remember when I first started bug hunting? I used to think looking into JS files was unnecessary — would I really find bugs in …
Read more
2023

How One Bug Scored Me Double Rewards!

Good day! I hope you are well. I’ll get straight into a couple of bugs I found a while ago in a private program on HackerOne. …
Read more