Sitemap
Mr. Plan ₿ Publication

Welcome to Mr. Plan ₿ Publication! A space for both beginners and experienced writers to promote their articles. Discover the secrets to a strong presence and amplify the impact of your words! 🚀📝 #MediumTips #WritersCommunity

“The Two “Boring” Security Flaws That Just Earned Me $60"

4 min readOct 9, 2025

--

Let me tell you about my most frustrating week as a bug bounty hunter. I’d spent 40 hours testing a major fintech company, finding absolutely nothing. No SQLi, no XSS, no business logic flaws. I was ready to give up.

Then I remembered: when you can’t find the fancy bugs, find the stupid ones.

free link

Press enter or click to view image in full size

Two hours later, I’d submitted two reports that earned me $60. Here’s exactly what I found.

The Password Reset Token That Wouldn’t Die

I was testing a popular project management tool. Like any good hunter, I went straight for the password reset flow.

The Process:

  1. I requested a password reset for my test account
  2. Got the email with a link like: https://app.com/reset-password?token=abc123def456
  3. Used the link, changed my password — success

But then I got curious. What if I used that same link again?

I copied the URL from my browser bar, opened an incognito window, and pasted it. The page loaded with a “Enter new password” form. I held my breath and typed password123.

It worked. The same token worked a second time.

--

--

Mr. Plan ₿ Publication

Published in Mr. Plan ₿ Publication

Welcome to Mr. Plan ₿ Publication! A space for both beginners and experienced writers to promote their articles. Discover the secrets to a strong presence and amplify the impact of your words! 🚀📝 #MediumTips #WritersCommunity

Aman Sharma

Written by Aman Sharma

| Data Enthusiast | SQL | Python | Power BI | ML | Exploring Cybersecurity & Bug Bounty | Sharing real-world analytics, dashboards & security insights.

Responses (1)