PinnedEhtesham Ul Haq·Apr 19Why I Built The Hidden Finds — A Real-World Approach to SaaS Security and Bug BountyFree Article Link: Click for free!A response icon4A response icon4
PinnedInInfoSec Write-upsbyEhtesham Ul Haq·Apr 24, 2025Bug Hunting for Real: Tools, Tactics, and Truths No One Talks AboutFree Article Link: Click for free!A response icon11A response icon11
InInfoSec Write-upsbyEhtesham Ul Haq·5d agoFrom User Enumeration to PII Exposure: Chaining Two APIs Into a $2,000 BugFree Article Link: Click for free!
InInfoSec Write-upsbyEhtesham Ul Haq·May 25How a GraphQL Invitation Flow Exposed Users at ScaleA normal invite feature revealed registered accounts, internal GraphQL identifiers, and user metadata through an overly detailed API…
InInfoSec Write-upsbyEhtesham Ul Haq·Mar 25From Delaying Certifications to Passing eJPT: My Real JourneyFree Article Link: Click for free!
InInfoSec Write-upsbyEhtesham Ul Haq·Feb 17Breaking the Trust Boundary: SSRF via a Misconfigured Sentry TunnelFree Article Link: Click for free!
InInfoSec Write-upsbyEhtesham Ul Haq·Jan 5Breaking the Same-Origin Policy: A Dive into a CORS MisconfigurationFree Article Link: Click for free!
InInfoSec Write-upsbyEhtesham Ul Haq·Dec 3, 2025Reflected XSS in OAuth Callback EndpointFree Article Link: Click for free!
InInfoSec Write-upsbyEhtesham Ul Haq·Oct 25, 2025Google Cybersecurity Certificate — and Why It’s the Easiest Way to Step Into the FieldFree Article Link: Click for free!
InInfoSec Write-upsbyEhtesham Ul Haq·Sep 15, 2025BurpSuite vs Caido: Rethinking Proxy Tools for Bug HuntersFree Article Link: Click for free!