HACKERBADGER

Breaking things. Writing it down.

HACKERBADGER
Visual_ID: HACKERBADGER

Latest Research

Hacker's Paradise: Full-Response SSRF to Internal Admin Service

2026.06.03
BugForge medium Full-Response SSRF

#ssrf #full-response-ssrf #internal-service #broken-access-control #cwe-918 #bugforge

DiceForge: Authentication Bypass via Spoofable Client-IP Header

2026.06.03
BugForge easy Authentication Bypass via Spoofable Client-IP Header

Part 1: Pentest Report

#access-control #header-spoofing #ip-allowlist #fuzzing #bugforge

CopyPasta: API Token Disclosure to Dual-Auth Admin Takeover

2026.06.03
BugForge easy API Token Disclosure + Dual-Auth Bypass

#api-security #broken-authentication #information-disclosure #privilege-escalation #cwe-200 #cwe-287 #bugforge

Cafe Club: Readable SSRF to Internal Admin API

2026.06.03
BugForge easy Readable SSRF

#ssrf #readable-ssrf #internal-service #broken-access-control #cwe-918 #bugforge

Sokudo: JWT Signature Verification Bypass on a Legacy Route Mount

2026.05.28
BugForge easy JWT Signature Verification Bypass

#jwt #alg-none #authentication-bypass #version-prefix #broken-access-control #bugforge

Appointments: Blind Boolean SQL Injection in a Path Parameter

2026.05.22
BugForge easy Blind Boolean SQL Injection

Part 1: Pentest Report

#sqli #blind-sqli #boolean-based #path-parameter #bugforge
analytics

Activity Log

[2026.06.03] New writeup published: Hacker's Paradise: Full-Response SSRF to Internal Admin Service
[2026.06.03] New writeup published: DiceForge: Authentication Bypass via Spoofable Client-IP Header
[2026.06.03] New writeup published: CopyPasta: API Token Disclosure to Dual-Auth Admin Takeover
[2026.06.03] New writeup published: Cafe Club: Readable SSRF to Internal Admin API
[2026.05.28] New writeup published: Sokudo: JWT Signature Verification Bypass on a Legacy Route Mount
construction

Toolkit

web v0.3.0
Caido Workbench
SQLi and JWT workbench plugin for Caido proxy.
speed v1.2.0
Race
HTTP/2 single-packet race condition testing.
key v1.0.0
JWTForge
JWT creation, modification, and signing tool.
more_horiz
More Coming
Additional tools in development.