HACKERBADGER
Breaking things. Writing it down.
Latest Research
Gift List: OTP Recipient Manipulation → Admin Access
2026.04.09Overview Platform: BugForge Vulnerability: OTP Recipient Manipulation (Authentication Bypass) — admin login send-code endpoint accepts arbitrary usernam...
Copypasta: UNION-Based SQL Injection
2026.04.08Overview Platform: BugForge Vulnerability: SQL Injection (UNION-based) — share_code path parameter concatenated directly into SQL query Key Technique:...
Tanuki: JWT None-Algorithm Bypass
2026.04.07Overview Platform: BugForge Vulnerability: JWT None-Algorithm Bypass leading to admin privilege escalation Key Technique: Forging an unsigned JWT with...
Cheesy Does It: Client-Side Price Tampering
2026.04.06Overview Platform: BugForge Vulnerability: Client-Side Price Tampering — Server Trusts Client-Sent Prices Key Technique: Modifying the amount, unit_pr...
Cafe Club: Business Logic — Till Payment Bypass
2026.04.06Overview Platform: BugForge Vulnerability: Business Logic Flaw — Hidden Purchase Type Bypasses Payment Key Technique: Fuzzing the checkout type parame...
Tanuki: IDOR on User Statistics Endpoint
2026.03.31Overview Platform: BugForge Vulnerability: Insecure Direct Object Reference (IDOR) on User Statistics Endpoint Key Technique: Path parameter manipulat...