Zero Click ATO via Systemic Mass Assignment: The Phantom Hand Most researchers? They’re just scrolling. They see some random JSON field in a proxy log that isn’t in the UI and think, “Whatever …
From medium.comSearch
PortSwigger Lab Write-up: Bypassing Brute-Force Protection via JSON Arrays
medium.com/@marwan20hisha…
#bugbounty #bugbountytips #bugbountytip
1
3
187
$210 Bounty — The Ghost in the API: How I Scraped “Deleted” Users (And Survived a 2-Month Triage…
systemweakness.com/210-bounty-the…
#bugbounty #bugbountytips #bugbountytip
$210 Bounty — The Ghost in the API: How I Scraped “Deleted” Users (And Survived a 2-Month Triage…
When a user clicks “Delete Account,” is their data really gone? A deep dive into Excessive Data Exposure, the illusion of “Soft Deletes,”…
From systemweakness.com 5
344
$STRK at Risk: Why Dismissing Security Reports as “AI Slop” is a Critical Mistake
blog.blockmagnates.com/strk-at-risk-w…
#bugbounty #bugbountytips #bugbountytip
$STRK at Risk: Why Dismissing Security Reports as “AI Slop” is a Critical Mistake
A deep dive into a Logic Bypass in Starknet Attestation and a lesson in failed responsible disclosure.
From blog.blockmagnates.com 774
3
233
You Can Find This Bug in ANY Website (How I Changed P5 to P1 Using Chain Vulnerability)
medium.com/@aktamil13/you…
#bugbounty #bugbountytips #bugbountytip
2
10
425
The Bug That Slipped: Stale Balance Accounting in YieldBasis (Sherlock Contest)
medium.com/@talfao_94085/…
#bugbounty #bugbountytips #bugbountytip
5
341
Finding an IDOR in User Profile API: A $15,000 Journey to Critical
xalgord.medium.com/finding-an-ido…
#bugbounty #bugbountytips #bugbountytip
🐛💰🔓🎯 Finding an IDOR in User Profile API: A $15,000 Journey to Critical
How I discovered a critical Insecure Direct Object Reference vulnerability that allowed unauthorized access to any user profile — and how…
From xalgord.medium.com 4
21
855
The Zero to Hero Guide to Bug Bounty Hunting: A Comprehensive Roadmap by Xalgord xalgord.medium.com/the-zero-to-he… #bugbounty #bugbountytips #bugbountytip
The Zero-to-Hero Guide to Bug Bounty Hunting: A Comprehensive Roadmap
Based on the insights from “The Best Way to Learn Bug Bounty Hunting” by CyberFlow
From xalgord.medium.com 1
3
236
Subfinder Subdomains Dhundho Like an Elite Hacker! (Hinglish Mein)
medium.com/@HackerMD/subf…
#bugbounty #bugbountytips #bugbountytip
1
8
621
Web Security Series #11 — Exploiting Stored Cross-Site Scripting (Stored XSS)
medium.com/@laibakashif00…
#bugbounty #bugbountytips #bugbountytip
10
536
How I Bypassed SSO to Access Sony’s Internal AI Chat Assistant (Broken Access Control)
medium.com/@dev_fr_/how-i…
#bugbounty #bugbountytips #bugbountytip
4
16
761
Security Misconfiguration — The #2 Vulnerability on the Web ⚙️
medium.com/@vedanthore/se…
#bugbounty #bugbountytips #bugbountytip
1
3
652
Bypassing Rate Limit via Race Condition by Sewilam medium.com/@Sewilam/bypas… #bugbounty #bugbountytips #bugbountytip
Bypassing Rate Limit via Race Condition
بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيم
From medium.com 5
26
901
نصيحة من البج هانترز
بتضبط يومك ما بين مذاكرة ثغرة وقراءة writeups والهانتيج ازاي ؟
وهل فيه ناس مثلا مخصصة أنها تذاكر يوم وتهانت يوم وكده ولا ايه بردو ؟
#bugbountytips
2
86
Password Strength Policy Bypass via Server-Side Validation Flaw
hackerone.com/reports/3523703
#bugbounty #bugbountytips #bugbountytip
Tucows (VDP) disclosed on HackerOne: Password Strength Policy...
It was found that the password strength policy was only enforced in the browser but not on the server side.
From hackerone.com 2
13
803
Building a Hacker Assistant with Python + Ollama
medium.com/@RyanMaxiemus/…
#bugbounty #bugbountytips #bugbountytip
1
13
695
⚡ Password Strength Policy Bypass via Server-Side Validation Flaw
👨🏻💻 2026 ➟ Tucows (VDP)
🟨 Low
💰 None
🔗 hackerone.com/reports/3523703
#bugbounty #bugbountytips #cybersecurity #infosecComfWD
1
15
679
Tomghost [Try Hack Me] machine Walkthrough :
medium.com/@amroubekhedda…
#bugbounty #bugbountytips #bugbountytip
5
554
Cross-Site Scripting (XSS) Explained: How a “Low Severity” Vulnerability Leads to Enterprise…
medium.com/@Err0rr0rre./c…
#bugbounty #bugbountytips #bugbountytip
12
633
