ASAbdulaziz Saadinblog.abdulaziz-d.com·May 21 · 6 min readIDOR in Government Ownership API Exposed Private Business Owner PII via CR Number EnumerationSeverity: HighBounty Awarded: $1,506Program: Private Bug BountyPlatform: Bugbounty.sa Some IDORs are obvious immediately. You change an ID. Someone else’s data appears. Easy. Others look harmless at f00
ASAbdulaziz Saadinblog.abdulaziz-d.com·May 18 · 9 min readZero-Click Stored XSS in Chat: When “Just Open the Window” Is EnoughSeverity: HighBounty Awarded: $394Program: Private Bug BountyPlatform: Bugbounty.sa Most chat XSS bugs are noisy. You send a payload. The victim has to click something. Refresh the page. Open the mes00
ASAbdulaziz Saadinblog.abdulaziz-d.com·May 15 · 8 min readFrom Username Enumeration to Subscriber PII: Chaining 3 Weak Findings in a Telecom EcosystemSeverity: MediumBounty Awarded: $560Program: Private Bug Bounty Most hunters have encountered login enumeration and immediately deprioritized it. Different response. Different redirect. Different word20