Web
2025
How I Found an Account Takeover Bug in the Forgot Password Flow
·801 words·4 mins
How I Found a $3000 IDOR Vulnerability in a Delivery App
·1045 words·5 mins
2024
Bypassing Rate Limit in GraphQL
·1526 words·8 mins
Exploiting DOM for Open Redirect Attacks
·1735 words·9 mins
HTTP Parameter Pollution vs Mass Assignment
·1176 words·6 mins
API Basics: A Hacker's Starter Guide
·1874 words·9 mins
Server Side Parameter Pollution in Rest API path parameter
·1441 words·7 mins
2022
Broken Object Level Authorization Vs. Broken Functionality Level Authorization | API Hacking
·2421 words·12 mins