☕ When a REST Route Spills the Beans: Finding an Author-enumeration Bug (CVE-2023–5561)There are two truths I live by: one, always keep coffee within arm’s reach; two, curiosity + an API = bad decisions that turn into CVEs…Oct 30Oct 30
The day Wayback pointed me to an admin panel — and why scope still wins ☕️I love quick wins. I love poking at weird URLs. I love coffee. What I don’t love: accidentally wandering into infrastructure that’s…Oct 24Oct 24
How an OAuth Misconfiguration Led to Account Takeover☕ The Coffee-Fueled ReconSep 10A response icon1Sep 10A response icon1
☕ My First Critical Bug: Account Takeover with Just One Tiny LetterBug bounty is wild. Sometimes you fuzz for hours and find nothing. Other times, one tiny character can open the door to a Critical Account…Sep 5A response icon3Sep 5A response icon3
🔐 How I Found Facebook and Google API Keys Hardcoded in an Android App (and Why That’s a Bad Idea)☕ Reverse engineering APKs is fun… until you stumble upon production secrets sitting in plain sight.Jul 12Jul 12
🔐 I Found a Hardcoded Google API Key in a Popular Food App (and It Was Too Easy 🍟🔑)☕ “Woke up, scanned an APK, found a secret. Just hacker things.”Jul 5Jul 5
🛰️ So… I Made a Server Call Me Back. Unauthenticated SSRF via XML-RPCOne fine evening, while sipping coffee stronger than my will to live, I accidentally made a server talk to me. Literally.Jun 30Jun 30
🧠 XML-RPC Open, phpinfo() Public — But They Came to Hire from My College 💀“Main toh sirf recon kar raha tha, lekin server bola… bhaiya sab kuch le jao.” — A bored student who just wanted coffee, not credentialsJun 15Jun 15