Multi-Tenant Authorization Bypass via Host Header Manipulation
Discovered a multi-tenant authorization bypass by manipulating the Host header, affecting tenant isolation in a private bug bounty program.
Articles on application security, bug bounty and web security.
Discovered a multi-tenant authorization bypass by manipulating the Host header, affecting tenant isolation in a private bug bounty program.
How I leveraged Wayback Machine URLs to uncover a Server-Side Request Forgery vulnerability leading to internal file access in a production system.
How I used Wayback Machine to discover an SSRF vulnerability leading to AWS metadata exposure in a private program.
How I found an SQL injection vulnerability by staying patient and focused on a long-term target.
I dedicated 20 hours to a private bug bounty program and share my methodology, mindset and findings.
How exposed Spring Boot Actuator endpoints can lead to critical vulnerabilities in real bug bounty programs.
An interesting and somewhat sad story involving LFI and SSRF chains found exactly one year into bug bounty.
Found a stored XSS in an HR application integrated system while testing name field parameters.
A Server-Side Request Forgery (SSRF) I found on a large-scope program. Full recon process included.
My last reflected XSS write-up before moving on to more complex vulnerabilities.
Found a reflected XSS on 8x8 within 3 minutes using subdomain enumeration and a simple payload.
My first bug bounty writeup. Found an XSS vulnerability on a Sony subdomain via subdomain enumeration and parameter fuzzing.