Just got awarded $8,500 on @Bugcrowd for uncovering a security misconfiguration leading to data exposure.
My highest single bounty ever. No AI, just old-school research and a lot of patience.
The grind pays off <3
#bugbounty#infosec
Critical vulnerabilities doesn't have to be complex or have a CVE - @deepseek_ai publicly exposed their internal ClickHouse database to the world, without any authentication at all, and leaked sensitive data.
No one is safe from security mistakes, follow along to learn more π§΅
Frans Rosen was on the pod last week and dropped some mind-bending X-Correlation Injection research on us.
Including these gems on how to test for it...
1/7
This is the thread I wish someone created for me when I started participating in bug bounty! π
Not everyone shares these methods... but
Here are a few tips to help you identify & exploit more IDOR vulnerabilities! π€
π§΅ π