← SecurityCédric MerlinFREN

Security galaxy Case 1 of 5

Finding the flaws that tools miss

The problem

Automated tools find the known flaws. The most serious ones hide in the logic specific to each application.

What I did

01

A clear framework

I start from an authorised program, a written scope and the program’s rules.

02

Understand first

I understand the application before testing it.

03

Minimal proof

I prove the flaw with the bare minimum, without touching anyone’s data.

04

Report and retest

I write the report, the vendor fixes the flaw, then I retest to confirm the fix.

Diagram: the method in four beatsA timeline in four beats: framework, analysis, proof, fix. A browser, a filter and an application are connected. A flag marks the proof on the application, then a report goes to the vendor, the filter is closed again, the check is validated and the padlock closes.programscoperulesbrowserfilterapplicationframeworkanalysisprooffix

The result

Rewarded on YesWeHack, Bugcrowd and Yogosha.

Types of flaws

  • Bypass of perimeter protections (web application firewall, automated filtering)