Exploiting Unprotected Functionality to Access User Profiles
How searching for legacy applications and leveraging URL history archives led to unauthorized access and modification of sensitive user profiles, earning a $500 bounty.
Samidu Nimsara // nmsr
Role: Application Security Researcher & Bug Bounty Hunter
Origin: Sri Lanka
Handle: hackerone.com/nmsr
Focus: API Security · IDOR · Broken Access Control · Web Pentesting
// @nmsr on HackerOne · @samidunimsara on GitHub
Application Security Researcher & Bug Bounty Hunter from Sri Lanka.
IDOR, privilege escalation, object-level auth bypass
REST/GraphQL endpoint testing, mass assignment, rate limiting
OWASP Top 10, authentication flaws, business logic
Subdomain enum, JS analysis, attack surface mapping
How searching for legacy applications and leveraging URL history archives led to unauthorized access and modification of sensitive user profiles, earning a $500 bounty.
Analyzing JWT verification flaws and signature validation vulnerabilities to elevate privileges from guest to administrator.
My workflow for harvesting hidden endpoints and API credentials from minified Webpack chunks using custom regex pipelines.