WRITEUP_TERMINAL
V.1.0 // SECURITY
Application Security Research

SECURITY WRITEUPS

A curated collection of real-world application security research, vulnerability disclosures, and technical writeups.
Manual testing · Source code analysis · Business logic exploration
#BrokenAccessControl #IDOR #BOLA #BusinessLogic #Auth #APIsecurity #BugBounty
▹ PUBLISHED ON
cybersecuritywriteups.com 2,9K+ followers
infosecwriteups.com 87K+ followers

WRITEUP_INDEX

5 articles
MFA Bypass
Authentication Authorization

The MFA Bypass That Wasn't an MFA Problem

CSWP cybersecuritywriteups.com

An investigation into an apparent MFA bypass that ultimately revealed broken API authorization, demonstrating why strong authentication cannot compensate for flawed backend access control.

Read article
Email Verification Bypass
Authentication State Management

How I Found an Email Verification Bypass on an AI Freelance Platform

Infosec infosecwriteups.com

A real-world email verification bypass caused by inconsistent state management between the registration and email verification flows, allowing accounts to be created with unverified email addresses.

Read article
Negative Shipping
Business Logic E-commerce

From Quantity Manipulation to Negative Shipping Costs

CSWP cybersecuritywriteups.com

A business logic flaw in an e-commerce application that allowed manipulation of order calculations through unexpected quantity values, resulting in negative shipping costs.

Read article
Org Access
Broken Access Control Lifecycle

I Was Removed From the Organization, But My Access Still Worked

CSWP cybersecuritywriteups.com

A case study showing how access remained valid after organizational membership was revoked, highlighting common authorization and access lifecycle failures.

Read article
IDOR
IDOR BOLA

From a Simple Profile Endpoint to a 100k+ User IDOR on HackerRank

CSWP cybersecuritywriteups.com

A seemingly harmless profile endpoint led to an authorization flaw affecting more than 100,000 user accounts.

Read article
Responsible Disclosure — all writeups follow responsible disclosure practices and exclude sensitive information that could impact users or organizations.

ABOUT_ME

I'm an Application Security Engineer and Security Researcher with a focus on application security, API security, business logic vulnerabilities, and authorization flaws.