HACKERBADGER
Breaking things. Writing it down.
Latest Research
OtterGram: IDOR on Profile Update
2026.04.11Overview Platform: BugForge Vulnerability: Insecure Direct Object Reference (IDOR) — Arbitrary Profile Modification Key Technique: Manipulating the id...
Galaxy Dash: Server-Side Prototype Pollution
2026.04.11Overview Platform: BugForge Vulnerability: Server-Side Prototype Pollution → Price Bypass Key Technique: Exploiting vulnerable deep merge on organizat...
Gift List: OTP Recipient Manipulation → Admin Access
2026.04.09Overview Platform: BugForge Vulnerability: OTP Recipient Manipulation (Authentication Bypass) — admin login send-code endpoint accepts arbitrary usernam...
Copypasta: UNION-Based SQL Injection
2026.04.08Overview Platform: BugForge Vulnerability: SQL Injection (UNION-based) — share_code path parameter concatenated directly into SQL query Key Technique:...
Tanuki: JWT None-Algorithm Bypass
2026.04.07Overview Platform: BugForge Vulnerability: JWT None-Algorithm Bypass leading to admin privilege escalation Key Technique: Forging an unsigned JWT with...
Cheesy Does It: Client-Side Price Tampering
2026.04.06Overview Platform: BugForge Vulnerability: Client-Side Price Tampering — Server Trusts Client-Sent Prices Key Technique: Modifying the amount, unit_pr...