I found a logic flaw that grants me free add-ons with the product, and confirmed there is no price check on the checkout!
They closed my report as N/A just because "most of the times purchases go through a manual review process".
That's unfair my role is to test WEB APPLICATIONS!
Yay, I scored a reward on @Bugcrowd for an IDOR.
Quick overview:
While testing a shopping site I noticed a special offer that was intended for only one item, and by using another item’s ID in the request I got a juicy discount on it.
Just scored a bounty on @Bugcrowd, l just love Logic flaws ❤️.
Always try to break the logic of the application and force it to do things it's not supposed to do. Manipulating items, key components, parameters can reveal a lot of logic flaws.
#ItTakesACrowd#bugbounty
Hey guys, this program has set waf restrictions right after I submitted these reports, now they are not reproducible.
Will they be accepted?
#bugbounty
Need help, This issue got fixed and the customer requested a retest, I confirmed it was resolved then I noticed another similar bug but different outcome, I submitted it and got closed as N/A, they told me that the customer should fix it both ways while this is still unresolved.
Need help, This issue got fixed and the customer requested a retest, I confirmed it was resolved then I noticed another similar bug but different outcome, I submitted it and got closed as N/A, they told me that the customer should fix it both ways while this is still unresolved.
Alhamdulilah, My first valid bug in 2024.
if you are testing a shopping site add something to your cart and change the quantity to a negative number, you might get a discount 😂, in my case the attacker can’t complete the purchase so it got rated as P4
236 Followers 563 FollowingBug Bounty Hunter | Web App Hacker | Red Team Specialist | Finding vulnerabilities, exploiting weaknesses, and securing the web one app at a time. ▂▃▄▅▆▇█
129K Followers 60 FollowingProviding Cyber Threat Intelligence from the Dark Web & Clearnet: Breaches, Ransomware, Darknet Markets, Threat Alerts & more. https://t.co/Fi7VW9lg94
51K Followers 601 FollowingFather | Lawyer | Bug Bounty Hunter | Complete newbie | Every Law has its own Bugs. https://t.co/Cwuy2zfF8N https://t.co/Bd9ltJWS5X
198K Followers 67 FollowingOfficial FBI Most Wanted X. Submit tips at https://t.co/YUIWyE7Isd. Public info may be used for authorized purposes: https://t.co/IlbUmBNuqu.
2K Followers 621 FollowingPentester at Thales DIS | OSCP | Bug Bounty Hunter | Researcher | Ethical Hacker | Honoring my father, a hacker of the early days | ckj0756 | Icare
9K Followers 1K Following📍 @yeswehack (aka Hisxo) - I love to break things (and I'm paid for that) - Bug Hunter
🔗 Check my Github repository https://t.co/Sj3prhiZyu
#BugBounty
22K Followers 55 Following#BHMEA25 | @TahalufGlobal @SAFCSP in assoc. with @BlackHatEvents | Dec 2-4 2025 📍Riyadh Exhibition and Convention Center, Malham