zax
@itsz4x
Followers
1K
Following
8K
Statuses
803
Security Researcher | Bug Hunter 🐞 Let's hack hack and more hack ☠️
Bangladesh
Joined March 2014
Alhamdulillah, I was awarded a $1,000 bounty on @Hacker0x01! #Bug: unauthorized access #TogetherWeHitHarder #hackerone #bugbounty
4
0
56
@MiniMjStar @Hacker0x01 actually kind of same but fetched data from a feature called planning console
1
0
1
@MiniMjStar @Hacker0x01 I was trying access control issues so I was collecting endpoints. Then I got a GET request which wasn't vulnerable then I changed it to POST & mistakenly made the request with user old session then I got the issue. So, here the POST request was vulnerable to unauthenticated acces
1
0
2
Alhamdulillah, I was awarded a $1,350 bounty on @Hacker0x01! #Bug: Access control 🔥 #Tips: find out api endpoints from admin account then try to access them from low privilege user account #TogetherWeHitHarder #hackerone #bugbountytips #bugbounty
3
5
71