Bug Bounty
2025
How I Found an Account Takeover Bug in the Forgot Password Flow
        
        
        
      
  
  
  ·801 words·4 mins
  
  
  
      How I Found a $3000 IDOR Vulnerability in a Delivery App
        
        
        
      
  
  
  ·1045 words·5 mins
  
  
  
      2024
Bypassing Rate Limit in GraphQL
        
        
        
      
  
  
  ·1526 words·8 mins
  
  
  
      Exploiting DOM for Open Redirect Attacks
        
        
        
      
  
  
  ·1735 words·9 mins
  
  
  
      Exploiting insecure output handling in LLMs
        
        
        
      
  
  
  ·457 words·3 mins
  
  
  
      Indirect prompt injection
        
        
        
      
  
  
  ·740 words·4 mins
  
  
  
      Exploiting vulnerabilities in LLM APIs
        
        
        
      
  
  
  ·838 words·4 mins
  
  
  
      Exploiting LLM APIs with excessive agency
        
        
        
      
  
  
  ·540 words·3 mins
  
  
  
      What is LLM APIs and how they work?
        
        
        
      
  
  
  ·1031 words·5 mins
  
  
  
      HTTP Parameter Pollution vs Mass Assignment
        
        
        
      
  
  
  ·1176 words·6 mins