Found that just using a user ID could generate a valid session token, leading to account creation without proper authentication. Simple but high impact → triaged as P1.
Good reminder: auth & session logic needs deep testing 🔍
#BugBounty#CyberSecurity#AppSec#AuthBypass#P1
Working on hardware devices has been fun lately.
Recently crossed ~$20k in bounties from Amazon’s Device Vulnerability Research Program (mostly FireTV) on @Hacker0x01 .
A lot of learning along the way, especially around device-level security. Still have a few reports under review
Yay just got a $25k bounty from H1 /security program 🎉 We can say I was lucky to keep 50% of my bounty because I landed this report just a few days before the controversial no-grace-period 50% budget cut. I barely managed to catch my last train 😁
Today triaged 4 bug
> 2 bugs IDOR and LFI were found using AI. It discovered issues that I had previously missed during manual testing — really amazing 🥳🥳
> 2 bugs were found manually as usual
Let’s keep pushing forward!
#bugbounty#AI#IDOR#LFI
Just got a reward for a critical vulnerability submitted on @yeswehack -- Improper Access Control - Generic (CWE-284). https://t.co/wCFzv83uWT #YesWeRHackers#HackThePlanet 🏴☠️
Day TWO of FIVE days of celebrating our 2 year ARCANUM-VERSARY! @arcanuminfosec
3rd Giveaway = FOUR seats to our new course by @the_IDORminator "Zero to [BAC] Hero" !
👍 1 Like = 1 Entry!
♻️ 1 Share = 2 Entries!
Winners announced 1/21! Syllabus link below 👇
Found a critical 0-click ATO in https://t.co/zRSPIyEUs0
Instead of reporting to the VDP, I'm considering reporting directly to the third-party service.
No idea if they have a program or pay, but worth the shot since the VDP offers $0.
#BugBounty#hackerone#idor#sqlinjection
First report of 2026 🥳🥰🌹
Sometimes services behave as if they have authentication, it's just a matter of how it's added. For those in JSON format, definitely try this: "--headers="Content-Type: application/json\nAuthorization: Bearer [TOKEN_HERE]" \"
payload ; {"username":"testuser';SELECT PG_SLEEP(5)--"}
#bugbounty #bugbountytips #sqlinjection
@intigriti