DIRECTORY_INDEX()
Bug Bounty Writeups
Security vulnerability discoveries and bug bounty writeups
OBJECTS004SORTED BY DATE ↓
/POSTS
Published files
Real findings, reproducible techniques, and lessons from production systems.
CASE_004HIGH
POSTS / IDOR
How I Scored $2K via an Easy IDOR
A predictable support-ticket reference exposed cross-account conversations, attachments, and replies.
2025-02-26 · 2 MINREAD_REPORT() ↗
CASE_003HIGH
POSTS / RCE
How I RCE'd the Largest RU Company
How favicon reconnaissance and an exposed Java Debug Wire Protocol service led to remote code execution.
2021-08-19 · 2 MINREAD_REPORT() ↗
CASE_002HIGH
POSTS / RECON
How I Scored 1K Bounty Using Waybackurls
How archived URLs exposed valid user tokens and turned one reconnaissance command into a $1K bounty.
2021-08-03 · 2 MINREAD_REPORT() ↗
CASE_001MEDIUM
POSTS / XSS
Tale of XSS in Angular
Finding two reflected XSS vulnerabilities in an Angular application through automated subdomain monitoring and framework-aware testing.
2021-08-01 · 1 MINREAD_REPORT() ↗