TAG_QUERY()
#Bugbounty
5 case files connected to this signal.
MATCHES005QUERY COMPLETE
CASE_007CRITICAL
RESEARCH / BUGBOUNTY
Hunting Account Takeovers in the Wild West of MCP OAuth Servers
How misconfigured Dynamic Client Registration in MCP OAuth servers enables one-click account takeover attacks against AI-integrated platforms
2026-01-24 · 7 MINREAD_REPORT() ↗
CASE_004HIGH
POSTS / IDOR
How I Scored $2K via an Easy IDOR
A predictable support-ticket reference exposed cross-account conversations, attachments, and replies.
2025-02-26 · 2 MINREAD_REPORT() ↗
CASE_005HIGH
RESEARCH / RECON
Abusing URL Shorteners for Fun and Profit
Mining archived short links to recover private invitations, tokens, and forgotten application flows.
2025-02-26 · 3 MINREAD_REPORT() ↗
CASE_003HIGH
POSTS / RCE
How I RCE'd the Largest RU Company
How favicon reconnaissance and an exposed Java Debug Wire Protocol service led to remote code execution.
2021-08-19 · 2 MINREAD_REPORT() ↗
CASE_002HIGH
POSTS / RECON
How I Scored 1K Bounty Using Waybackurls
How archived URLs exposed valid user tokens and turned one reconnaissance command into a $1K bounty.
2021-08-03 · 2 MINREAD_REPORT() ↗