Hall of Fame

An authoritative technical repository of high-impact security research, responsible disclosures, and recognized contributions to global cybersecurity infrastructure.

Healthcare Booking Platform

Cloud Security & VAPT Audit

5 DISCLOSURES DISCOVERED

Firestore Full Read/Write Access

Critical Severity

Critical misconfiguration in Firebase security rules enabled recursive unauthenticated CRUD access to the entire production database. This vulnerability provided a direct path to exfiltrate patient health records, administrator credentials, and sensitive internal metadata.

Attack VectorBroken Auth (No Rules)
Technical ImpactFull DB Compromise
Current StatusReported / Under Review

Mass Data Exfiltration via API

Critical Severity

A failure in the hospital query endpoint permitted bulk retrieval of Personal Identifiable Information (PII). By exploiting missing rate-limiting and weak object scoping, over 100,000 sensitive records were accessible via simple automated scripts.

Attack VectorInsecure Object Ref
Technical ImpactMass PII Exposure
Current StatusReported / Under Review

Unauthorized Plan Upgrade

Critical Severity

Direct write permissions on sensitive user fields allowed for a financial logic bypass. An attacker could elevate their own subscription tier to 'Premium' by manually modifying database flags, completely bypassing the Stripe payment integration.

Attack VectorPrivilege Escalation
Technical ImpactFinancial Logic Bypass
Current StatusReported / Under Review

IDOR via Predictable Document IDs

High Severity

Patient appointment logs were indexed using MD5-hashed email addresses. Since email addresses are discoverable, this predictable resource naming allowed for targeted IDOR attacks to view private medical consultation details.

Attack VectorBOLA (Broken Object Auth)
Technical ImpactTargeted PII Leak
Current StatusReported / Under Review

Meta Ads / CERT-In

Cybercrime Infrastructure Research

NATIONAL IMPACT ALERT

Paid Scam Infrastructure (UPI Fraud)

High Severity

Mapped and disclosed a complex fraud network operating through Meta's advertising platform. The network leveraged compromised UPI IDs and automated bot-campaigns to conduct financial phishing. Evidence submitted to CERT-In for infrastructure takedown.

Attack VectorAutomated Fraud Ops
ImpactFinancial Fraud Prevention
StatusNational Agency Review

Institutional Systems

Internal Application Audits

FORMALLY ACKNOWLEDGED

IDOR in Feedback Portal

High Severity

Discovery of a critical authentication flaw in the institutional student feedback system. By manipulating numerical document identifiers, students could view, edit, or delete feedback entries belonging to any other user.

Attack VectorBroken Access Control
Technical ImpactData Anonymity Breach
StatusFixed / Acknowledged