THREAT INTEL // CASE BOARD

Research case files

Vertical dossiers from the lab — multi-stage RCE, broken trust boundaries, and infrastructure ghosts. Open a case file to read the full chain.

10 cases
2023
CASE-004 2023
WEB APPLICATION SECURITY
Free Diamond Memberships: Payment Logic vs Encrypted Add-On APIs

Reversing client-side AES on a hotel booking platform and abusing payment_method / membership flags to activate Diamond benefits without…

B2B Hotels // Membership Tiers // Purchase Add-Ons
Hotel Booking / Subscription Platform 2023-10-31
HIGH open file →
CASE-005 2023
WEB APPLICATION SECURITY
From Mass Assignment to Database Dump: When Type Confusion Becomes SQLi

How a profile-update mass-assignment bug, array injection, and verbose MySQL errors chained into error-based SQL injection and full…

Node.js API // Profile Update // MySQL
Node.js / Express / MySQL 2023-07-13
CRITICAL open file →
CASE-006 2023
WEB APPLICATION SECURITY
Account Takeover via SessionStorage Authorization

How a financial web app mixed cookie authentication with sessionStorage identity, user enumeration APIs, and OSINT-derived employee emails…

Financial SaaS // SessionStorage // User Lookup API
Financial Web Application 2023-03-30
CRITICAL open file →
CASE-007 2023
WEB APPLICATION SECURITY
CMS Privilege Escalation: Cognito Auth, localStorage Roles

Breaking a multinational CMS that used AWS Cognito for authentication but trusted a localStorage user_role flag for editor/publisher…

MNC CMS // Cognito // Content Publishing
ReactJS / AWS Cognito CMS 2023-03-25
HIGH open file →
CASE-008 2023
WEB APPLICATION SECURITY
Reversing Client-Side AES: When ‘Encrypted APIs’ Are Just Obscurity

How hardcoded AES-CBC keys and IVs in shared CDN JavaScript turned encrypted REST traffic into a fully automatable API surface — including…

Multi-App CDN // Encrypted REST // reCAPTCHA
Web / Android / iOS (shared API) 2023-02-15
HIGH open file →