The Bug That Slipped: Stale Balance Accounting in YieldBasis (Sherlock Contest)
medium.com/@talfao_94085/โฆ
#bugbounty #bugbountytips #bugbountytip
3
115
How I discovered a critical Insecure Direct Object Reference vulnerability that allowed unauthorized access to any user profile โ and howโฆ
From xalgord.medium.comBased on the insights from โThe Best Way to Learn Bug Bounty Huntingโ by CyberFlow
From xalgord.medium.comุจูุณูู ู ุงููููููู ุงูุฑููุญูู ูููฐูู ุงูุฑููุญููู
From medium.comIt was found that the password strength policy was only enforced in the browser but not on the server side.
From hackerone.com

A Real-World Bug Chain Story
From 0x0meowsec.medium.comIt started with a single parameter I wasnโt supposed to controlโฆ
From medium.com