research.sh — zsh — 132×42PID 31337
./sicksec --profile offensive --output public

Finding the bugs
between the specs._

INFO Independent security research on APIs, authentication, OAuth, GraphQL, and the strange behavior nobody documented.

[2026-01-24 00:00:00] Latest research node synchronizedScroll for case files ↓
QUICK_FILTER:tags7 OBJECTS FOUND
/VAR/LOG/SICKSEC

Case files

CRITICAL RESEARCHCASE_007
CASE_007 / RESEARCH / BUGBOUNTY

Hunting Account Takeovers in the Wild West of MCP OAuth Servers

How misconfigured Dynamic Client Registration in MCP OAuth servers enables one-click account takeover attacks against AI-integrated platforms

CASE_004HIGH
POSTS / IDOR

How I Scored $2K via an Easy IDOR

A predictable support-ticket reference exposed cross-account conversations, attachments, and replies.

2025-02-26 · 2 MINREAD_REPORT() ↗
CASE_005HIGH
RESEARCH / RECON

Abusing URL Shorteners for Fun and Profit

Mining archived short links to recover private invitations, tokens, and forgotten application flows.

2025-02-26 · 3 MINREAD_REPORT() ↗
CASE_006CRITICAL
RESEARCH / ATO

Account Takeover via an Unsanitized Facebook OAuth Redirect Scheme

How a one-character mutation in a mobile OAuth redirect scheme allowed authentication tokens to be intercepted by a malicious app.

2023-09-01 · 4 MINREAD_REPORT() ↗
CASE_003HIGH
POSTS / RCE

How I RCE'd the Largest RU Company

How favicon reconnaissance and an exposed Java Debug Wire Protocol service led to remote code execution.

2021-08-19 · 2 MINREAD_REPORT() ↗
CASE_002HIGH
POSTS / RECON

How I Scored 1K Bounty Using Waybackurls

How archived URLs exposed valid user tokens and turned one reconnaissance command into a $1K bounty.

2021-08-03 · 2 MINREAD_REPORT() ↗
CASE_001MEDIUM
POSTS / XSS

Tale of XSS in Angular

Finding two reflected XSS vulnerabilities in an Angular application through automated subdomain monitoring and framework-aware testing.

2021-08-01 · 1 MINREAD_REPORT() ↗
/PROC/METHODOLOGY

Attack surface

A living map of technologies, failure modes, and trust boundaries under active research.

AUTHENTICATIONAUTHORIZATIONINPUTINFRASTRUCTURE
whoami.txtRW-R--R--
SickSec
❯ whoami

SICKSEC

ROLE: Security Researcher & Bug Hunter
FOCUS: Web / API / GraphQL / OAuth
MODE: Stay curious

Finding bugs in production, breaking APIs for fun, and publishing the path that turns odd behavior into real impact.

search.sh — archive index
SEARCHING /INDEX.JSONTYPE TO QUERY

Enter a vulnerability, technique, technology, or article title.