HACKERBADGER
Breaking things. Writing it down.
Latest Research
Cheesy Does It: Refund Amount Manipulation
2026.04.13Overview Platform: BugForge Vulnerability: Business Logic — Unvalidated Client-Supplied Refund Amount Key Technique: Submit an arbitrarily large refun...
OtterGram: IDOR on Profile Update
2026.04.11Overview Platform: BugForge Vulnerability: Insecure Direct Object Reference (IDOR) — Arbitrary Profile Modification Key Technique: Manipulating the id...
Galaxy Dash: Server-Side Prototype Pollution
2026.04.11Overview Platform: BugForge Vulnerability: Server-Side Prototype Pollution → Price Bypass Key Technique: Exploiting vulnerable deep merge on organizat...
Gift List: OTP Recipient Manipulation → Admin Access
2026.04.09Overview Platform: BugForge Vulnerability: OTP Recipient Manipulation (Authentication Bypass) — admin login send-code endpoint accepts arbitrary usernam...
Copypasta: UNION-Based SQL Injection
2026.04.08Overview Platform: BugForge Vulnerability: SQL Injection (UNION-based) — share_code path parameter concatenated directly into SQL query Key Technique:...
Tanuki: JWT None-Algorithm Bypass
2026.04.07Overview Platform: BugForge Vulnerability: JWT None-Algorithm Bypass leading to admin privilege escalation Key Technique: Forging an unsigned JWT with...