Deep dives

In-depth write-ups of real-world vulnerabilities we found in companies' and organizations' systems — how we found them, how they chained together, and how we reported them to help the owners secure their systems. Plus the occasional bug bounty write-up.

RESPONSIBLE DISCLOSURE
by Marcel

Motokeska.cz – Payment Bypass for Free Vouchers, Plus QR Token Leaks and Location Exposure

Five flaws on motokeska.cz: a payment bypass handing out free vouchers, leaked QR tokens, and profile photos exposing GPS location.

broken-access-controllogic-flawprivacy-riskresponsible-disclosure
CZK 25,000
RESPONSIBLE DISCLOSURE
by Marcel

Planetum.cz – Chained Vulnerabilities Led to RCE

A single SQL injection on observatory.cz opened a chain that ended in administrative access and Remote Code Execution on planetum.cz — plus three further findings.

attack-chainsql-injectionremote-code-executionlateral-movementcrackingprivacy-riskxssresponsible-disclosure
declined
RESPONSIBLE DISCLOSURE
by Marcel

Reflected XSS at the České Budějovice Observatory

A reflected Cross-Site Scripting flaw in the search form of the České Budějovice Observatory websites, and what an attacker could quietly do with it.

xssbeef-frameworkresponsible-disclosure
won't fix
BUG BOUNTY
by Michal

Livesport bug bounty – Directory traversal at lsid.eu

Directory Traversal vulnerability was identified and responsibly reported through Livesport’s official bug bounty program.

path-traversalbug-bounty
$500
BUG BOUNTY
by Michal

Livesport - Vertical privilege escalation(s)

Business logic flaw that allowed manipulation with bonuses and competition results.

idorbusiness-logicprivilege-escalationbug-bounty
$200