Auth bypass on API token refresh
How a critical authentication bypass in *.northwind.com was found, reported to Northwind Cloud and fixed.
Write-ups from the researchers who found the bugs, guides on how they work, and advisories from the companies that fixed them. A write-up is tied to a real report, published under that program’s own disclosure policy.
A write-up on datacoconut is tied to a real report, and the program's own disclosure policy decides when it can be published. Here is exactly what that means.
Read it →How a critical authentication bypass in *.northwind.com was found, reported to Northwind Cloud and fixed.
Most researchers skim the scope and start testing. The half hour you spend reading it properly is the highest-value half hour of the engagement.
How a critical other in Webhook delivery service was found, reported to Orbit Payments and fixed.
How a critical sql / command injection in secure.meridianbank.com was found, reported to Meridian Bank and fixed.
Every report we received, what we paid, how long we took, and the things we got wrong. Published because a programme nobody can audit is marketing.