18 checklist card(s).
- From API Access Bypass to Campaign Takeover - Udaytrivedi
- When the Frontend Says “Invite Only” but the Backend Says Otherwise - redhunter01
- How an Unsecured API Endpoint Exposed 5,200+ Global Bank Records - CypherNova1337
- How I Discovered an API Authorization Flaw Exposing 100+ User Phone Numbers and Sensitive Campaign… - 4osp3l
- How a Simple API Misconfiguration Leaked PII of 100,000+ Users - Sagar Kirola
- Critical Exposure Of Algolia Key That Led to Production, Staging, and Draft Data - Adham Mohamed
- How a Locale Path Bypass Exposed 339,000 Media Objects and Multiple Cloud Backends - Tarek ElDemerdash
- Modern web applications depend heavily on JavaScript. - Rakesh Joshi
- A Couple’s Hunt: Hardcoded Credentials Lead to Internal Data Exposure & a $300 Bounty - Utaa
- How an exposed eXist-db REST interface revealed application collections, configuration files, and… - oldman
- Rate Limiting & API Abuse Bugs - Nitin yadav
- How One Exposed API Cost a Shipping Company $10,000 in a Few Hours - cyber security
- Bounty for an Out-of-Scope Vulnerability - Hemandhemanth
- API Recon — Mapping Every Hidden Endpoint - Nitin yadav
- Abusing Samsung Find’s Notification API to Send Trusted Emails to Arbitrary Recipients - danielelpsy
- Why HTTP QUERY Changes API Security Forever - Dhruv
- CVE-2023–35078 Unveiled: Ethical Vulnerability Discovery and Reporting By Me and My Hunting Buddy… - Rj07
- Introduction to API Hacking: A Free Course to Level Up Your Skills - Maisam Noyan