HackerOne · Public Program
Session-invalidation chain: refresh-token rotation without prior-token invalidation, logout endpoint cosmetic-only.
Disclosures
Öffentlich gemachte Security-Findings und Responsible-Disclosure-Arbeit. Jede Zeile ist eine Geschichte, jede Geschichte ist verifizierbar.
HackerOne · Public Program
Session-invalidation chain: refresh-token rotation without prior-token invalidation, logout endpoint cosmetic-only.
HackerOne · Public Program
Six exported Android activities without caller verification, enabling cross-app UI spoof with zero-permission PoC.
Responsible Disclosure · Private
Open CORS forwarder chained through cloud metadata to service-account token, granting broad read-access to the tenant.
Private RDP · Retail
Unauthenticated GraphQL path enabled enumeration of ~58M user profiles via single alias-batched request.
Hall of Thanks
Programme und Unternehmen die saubere Responsible-Disclosure-Arbeit anerkannt haben.
Kurzes Scoping-Gespräch, klares Angebot, Start in zwei bis vier Wochen.
Gespräch anfragen