← all topics

/blog/tags/bug-bounty

bug-bounty

2 articles

  1. From Search Results to Two CERT-In RecognitionsA restrained account of using indexed government-domain pages as reconnaissance leads, preserving evidence, and separating two CERT-In recognitions from unsupported conclusions.5 min read
  2. The Invoice Number Changed. Did the Authorization Decision?A historical invoice authorization concern recast as a controlled two-account method for testing and preventing broken object-level authorization.6 min read