kudos to @intigriti for stepping in and raising this to the company, which finally re-reviewed the issue and rewarded the remaining bounty aligned with Medium severity, as I initially reported.
Few weeks ago, I found a High severity #IDOR vulnerability on @Bugcrowd platform that led to ATO!
Once again, developers messed up by returning the session access token of the victim, allowing me to gain full access to the user's account.
#BugBounty#Hacking
I keep progressing on @Hacker0x01
bug bounty platform as this weekend I reported 3 valid cross-tenant IDOR #vulnerabilities (1 High, 2 Medium).
Less than 4 days and I got them all triaged - quite surprised but glad to see such speedy work of H1 triage team!
Digging through #JavaScript source code often reveals juicy endpoints not (intentionally?) exposed in the UI. They’re often highly vulnerable, specially when those are developed for internal use or potentially 'trusted' users. Cheers to the developers!🤘
Sweet High vulnerability on @Bugcrowd , breaking personal record!
IDOR allowed low-priv. user to change payment configurations of other companies 🤘
#bugcrowd#hacking#bugbounty
I've officially entered the overall Top 100 (currently ranked #98) on the @intigriti Bug Bounty platform — 120 valid vulnerabilities, and Top 1 in 3 private programs!
Looking forward to growing further & climbing even higher in the rankings.
#BugBounty#Intigriti#hacking
Reporting is the hardest and most boring part of #BugBounty, but sometimes it's just worth it when companies appreciate good quality reports - kind bonus received on @intigriti platform!
#hacking#pentesting
Kudos to @intigriti's triage team - you guys make our research experience amazing with your speedy response times.
Always happy to help triaggers by making easy-to-follow reports ;)
#bugbounty#intigriti
Seems I've been busy lately on @intigriti#BugBounty platform. So far 1 Critical and quite a few High/Medium vulnerabilities were reported and already pending (16) in the pipeline
Another IDOR accepted in @Bugcrowd, close to reach 30 valid vulnerabilities reported in this platform and increasing the ones from BB.
Sadly, GUIDs are killing me due to BC's VRT / high complexity attack classification as P4.
bugcrowd.com/PlatasSec
An IDOR I reported some days ago classified as Medium severity has been increased to High by the company as their dev team managed to find another and even more severe issue due to my report - thanks @intigriti, best #BugBounty platform in the space!
Just stacked some $BTC for long term-plans. On the flip side, I made a bank transfer over the weekend and still waiting for it to 'arrive'...traditional banking system at the top of innovation, isn't it? 👀😂 Even if it's just playing around with fake numbers though.
After some time off - working and getting cybersecurity certifications - I'm just back cooking some fresh content for my #YouTube channel! Stay tuned
📹 youtube.com/@platassec