Hunters🐺,
I have a new API Hacking write-up to share with you, this one is really crazy because it’s just take some hours to find this API bug. You can read about other API Bugs:
I am not consistent with my hunting write-ups because of my recent job but thanks whoever reading my write-ups.
Introduction
Just after submitting API bug to my regular bug bounty program, I have decided to search for one of my faviourite brand bug bounty program and It turns out they have self-hosted bug bounty program.
I picked the global subdomain and ran subfinder for quick subdomains of the global subdomain:
subfinder -d company.com --all --recursive | anew subs.txtI have got so many subdomains but one of them looks intersting let’s say it’s ghost.company.com, and I quickly opened this subdomain domain in my browser and It turns out this is a very new subdomain of this company.