HACKERBADGER

Breaking things. Writing it down.

HACKERBADGER
Visual_ID: HACKERBADGER

Latest Research

Vaultly: Account Takeover via Unbound Password-Reset Token

2026.06.10
BugForge hard Password-Reset Account Takeover

#account-takeover #password-reset #broken-access-control #webapp #bugforge

Shady Oaks Financial: UNION-based SQL Injection

2026.06.10
BugForge easy UNION-based SQL Injection

#sqli #union-injection #cwe-89 #bugforge #webapp

Ottergram: Private Posts via Dual-Identifier Authorization Drift

2026.06.10
BugForge medium Broken Object-Level Authorization

#idor #broken-access-control #bola #client-side-security #dual-identifier #webapp #bugforge

Galaxy Dash: Broken Access Control via Writable Avatar Field

2026.06.05
BugForge medium Broken Access Control

Part 1: Pentest Report

#broken-access-control #idor #authorization-bypass #multi-tenant #bugforge

Hacker's Paradise: Full-Response SSRF to Internal Admin Service

2026.06.03
BugForge medium Full-Response SSRF

#ssrf #full-response-ssrf #internal-service #broken-access-control #cwe-918 #bugforge

DiceForge: Authentication Bypass via Spoofable Client-IP Header

2026.06.03
BugForge easy Authentication Bypass via Spoofable Client-IP Header

Part 1: Pentest Report

#access-control #header-spoofing #ip-allowlist #fuzzing #bugforge
analytics

Activity Log

[2026.06.10] New writeup published: Vaultly: Account Takeover via Unbound Password-Reset Token
[2026.06.10] New writeup published: Shady Oaks Financial: UNION-based SQL Injection
[2026.06.10] New writeup published: Ottergram: Private Posts via Dual-Identifier Authorization Drift
[2026.06.05] New writeup published: Galaxy Dash: Broken Access Control via Writable Avatar Field
[2026.06.03] New writeup published: Hacker's Paradise: Full-Response SSRF to Internal Admin Service
construction

Toolkit

web v0.3.0
Caido Workbench
SQLi and JWT workbench plugin for Caido proxy.
speed v1.2.0
Race
HTTP/2 single-packet race condition testing.
key v1.0.0
JWTForge
JWT creation, modification, and signing tool.
more_horiz
More Coming
Additional tools in development.