Manipulated All Files on Server of a HackerOne Target

2 weeks ago 21
BOOK THIS SPACE FOR AD
ARTICLE AD

AbhirupKonwar

Free Article Link: Click here!

whoami❓

I am Abhirup Konwar (aka LegionHunter). I work as a full-time bug hunter and part-time on personal malware development projects.🥷

I have reported over 1000 bugs on OpenBugBounty as well as on HackerOne and BugCrowd along with numerous Hall Of Fame programs including NASA, American Systems and self hosted VDP + BBP , with bugs belonging to both Client and Server Injection category, Sensitive Information Disclosure & Broken Access Control.

Article Brief

In this article, I will discuss very deep: the steps, methodology, thought process and what did I saw or observed that led me to this endpoint🤑 I can directly show the endpoint and finish this article, but you guys will keep asking , how did you get to this endpoint bro😏

What type of industry or market sector the target belongs to?

Finance, Healthcare, Retail & E-commerce, Technology, Telecommunications, Education, Media & Entertainment, Energy & Utilities, Government & Public Sector, Transportation & Logistics

Can we snoop into the developer’s github, monitor daily for changes made, one small mistake like leaving the basic encoded API key in the dev code comments , thinking…
Read Entire Article