HACKERBADGER
Breaking things. Writing it down.
Latest Research
Galaxy Dash: Server-Side Prototype Pollution
2026.04.11Overview Platform: BugForge Vulnerability: Server-Side Prototype Pollution → Price Bypass Key Technique: Exploiting vulnerable deep merge on organizat...
Gift List: OTP Recipient Manipulation → Admin Access
2026.04.09Overview Platform: BugForge Vulnerability: OTP Recipient Manipulation (Authentication Bypass) — admin login send-code endpoint accepts arbitrary usernam...
Copypasta: UNION-Based SQL Injection
2026.04.08Overview Platform: BugForge Vulnerability: SQL Injection (UNION-based) — share_code path parameter concatenated directly into SQL query Key Technique:...
Tanuki: JWT None-Algorithm Bypass
2026.04.07Overview Platform: BugForge Vulnerability: JWT None-Algorithm Bypass leading to admin privilege escalation Key Technique: Forging an unsigned JWT with...
Cheesy Does It: Client-Side Price Tampering
2026.04.06Overview Platform: BugForge Vulnerability: Client-Side Price Tampering — Server Trusts Client-Sent Prices Key Technique: Modifying the amount, unit_pr...
Cafe Club: Business Logic — Till Payment Bypass
2026.04.06Overview Platform: BugForge Vulnerability: Business Logic Flaw — Hidden Purchase Type Bypasses Payment Key Technique: Fuzzing the checkout type parame...