Write-upAuthentication bypass
Auth bypass on API token refresh
How a critical authentication bypass in *.northwind.com was found, reported to Northwind Cloud and fixed.
4 min22 days ago
Application security researcher focused on authentication, access control and API logic flaws. Full-time bug hunter; occasional CTF author.
First valid report on a program.
25+ critical severity findings.
Verified skill badge in api & graphql.
All-time platform reputation.
3 write-ups and guides on the Learn hub.
90%+ acceptance over 100+ reports.
| Severity | Finding | Program | Bounty |
|---|---|---|---|
| Critical | Auth bypass on API token refresh | Northwind | $8,000 |
| Critical | RCE in image-processing worker | Meridian | $12,000 |
| Critical | JWT signature not verified | Solstice | $9,000 |
| High | SSRF via webhook URL validator | Orbit | $3,000 |
| Low | Reflected XSS on ?q= search param | Auriga | $150 |
How a critical authentication bypass in *.northwind.com was found, reported to Northwind Cloud and fixed.
Most researchers skim the scope and start testing. The half hour you spend reading it properly is the highest-value half hour of the engagement.
How a critical sql / command injection in secure.meridianbank.com was found, reported to Meridian Bank and fixed.