Bypassing 2FA in a Public Bug Bounty Program: A $6000 JourneyAs a bug bounty hunter, uncovering vulnerabilities in public programs is both thrilling and rewarding. In this post, I’ll walk you through…May 4A response icon12May 4A response icon12
The P2 Bug You Could Miss Without Reading the DocumentationHi everyone,Nov 27, 2024A response icon3Nov 27, 2024A response icon3
The $2,200 ATO Most Bug Hunters Overlooked by Closing Intruder Too SoonBug hunting is a mix of technical skills, persistence, and curiosity. Sometimes, the simplest bugs are overlooked because of one thing —…Nov 20, 2024A response icon15Nov 20, 2024A response icon15
Bypassing Filters: SSRF Exploitation via DNS Rebinding with Just 1 in 30 Successful RequestsHey everyone, hope you’re all doing well! I wanted to share a cool bug story I came across a few months ago. It’s about an SSRF…Sep 29, 2024A response icon6Sep 29, 2024A response icon6
I Spent a Month on a Private Program and Earned $$$$$I hope you all are doing great. I’m tweeting about taking on challenge where I will spend an hour on one program and see how it goes.Sep 27, 2024A response icon7Sep 27, 2024A response icon7
What would I do if I start bug hunting from 0 again?Hi everyone,Sep 6, 2022A response icon10Sep 6, 2022A response icon10
A business Logic issue worth $1500Hello everyone,May 21, 2022A response icon4May 21, 2022A response icon4
Account verification code bypass lead to a $4000 bountyHello reader,May 8, 2022A response icon14May 8, 2022A response icon14
You need to hear this if you are new/want to start bug huntingHello everyone,Apr 27, 2022A response icon10Apr 27, 2022A response icon10
Full account takeover worth $1000 Think out of the boxHi everyone how are you doing today? I hope you are doing great and scoring lots of bounties. Today's story is about a bug I found on…Feb 15, 2021A response icon9Feb 15, 2021A response icon9