Wednesday, 30 September, 2026

Category: Bug Bounty

Bug bounty news, tips, and writeups


SSRF server-side request forgery guide

A practical, evergreen guide to SSRF: what server-side request forgery is, where it hides, how to confirm blind SSRF with out-of-band callbacks, how to escalate to cloud metadata and internal services, and how to bypass weak filters — ethically.


FortiWeb CVE-2026-26035 authentication bypass

FortiWeb CVE-2026-26035 lets an unauthenticated attacker log in as admin with any username and password when the wildcard RADIUS setting is on. The flaw, the fixed versions, and a practical bug-bounty methodology for finding authentication-bypass bugs.


Writing a bug bounty report

How to write a bug bounty report that gets accepted quickly: a specific title, a tight summary, numbered reproducible steps, hard proof, and a concrete impact statement.


How to find your first IDOR

A safe, beginner-friendly methodology for finding your first IDOR: map object references, understand ID formats, and test authorization by swapping between two accounts you own.