Bypassing HackerOne Report Ban Using API Key
安全研究员发现HackerOne平台漏洞,即使账户被禁也能通过创建API密钥绕过限制,成功向沙盒及真实项目提交报告,违反平台信任机制. 2025-6-5 05:49:31 Author: infosecwriteups.com(查看原文) 阅读量:12 收藏

How a Banned Researcher Could Still Submit Reports Using the REST API

Monika sharma

Summary

In this finding, Security researcher demonstrate a serious flaw in HackerOne’s platform enforcement. Even after being officially banned from submitting reports, Security researcher was able to bypass the restriction using an API key and submit reports to both sandbox and real programs — a direct violation of the platform’s trust and abuse-prevention mechanisms.

Steps to Reproduce

light3r contacted HackerOne support and had my account restricted from submitting any new reports. This restriction is confirmed in the screenshot below.

2. Attempt to Submit a Report via UI or Direct Request

After the ban, light3r tried creating a report directly — received a 403 Forbidden error as expected.

3. Create a Sandbox Program and API Key

light3r navigated to HackerOne’s settings and created an API key through the sandbox program.


文章来源: https://infosecwriteups.com/bypassing-hackerone-report-ban-using-api-key-061711e873c6?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh