# Finding the flaws that tools miss

Security galaxy · Cédric Merlin, CTO · https://merlin-cedric.fr/en/securite/bug-bounty/

Looking for vulnerabilities in an authorised program: written scope, analysis, minimal proof, report and retest.

## The problem

Automated tools find the known flaws. The most serious ones hide in the logic specific to each application.

## What I did

1. **A clear framework.** I start from an authorised program, a written scope and the program’s rules.
2. **Understand first.** I understand the application before testing it.
3. **Minimal proof.** I prove the flaw with the bare minimum, without touching anyone’s data.
4. **Report and retest.** I write the report, the vendor fixes the flaw, then I retest to confirm the fix.

## The result

Rewarded on YesWeHack, Bugcrowd and Yogosha.

## Types of flaws

- Bypass of perimeter protections (web application firewall, automated filtering)

---
Page: https://merlin-cedric.fr/en/securite/bug-bounty/ · Contact: contact@merlin-cedric.fr
