01
A clear framework
I start from an authorised program, a written scope and the program’s rules.
Security galaxy Case 1 of 5
The problem
What I did
01
I start from an authorised program, a written scope and the program’s rules.
02
I understand the application before testing it.
03
I prove the flaw with the bare minimum, without touching anyone’s data.
04
I write the report, the vendor fixes the flaw, then I retest to confirm the fix.
The result
Rewarded on YesWeHack, Bugcrowd and Yogosha.
Types of flaws