One User, Multiple Votes: A Race ConditionHey Hackers, I am Parth Narula. A penetration tester, bug hunter, red teamer and overall a security researcher. I live for those moments…6d agoA response icon16d agoA response icon1
The Invite That Took Over Accounts: A Logic FlawHey Hackers, I am Parth Narula. A penetration tester, bug hunter, red teamer and overall a security researcher. I live for those moments…Feb 22Feb 22
Logic Poisoning: How One Bad Review Broke RatingsHey Hackers, I am Parth Narula. A penetration tester, bug hunter, red teamer and overall a security researcher. I live for those moments…Feb 11A response icon2Feb 11A response icon2
IDOR Lets Attackers Choose Your Payment MethodHey Hackers, I am Parth Narula. A penetration tester, bug hunter, red teamer and overall a security researcher. I live for those moments…Feb 1A response icon1Feb 1A response icon1
A Simple IDOR That Ignored Platform LogicHey Hackers, I am Parth Narula. A penetration tester, bug hunter, red teamer and overall a security researcher. I live for those moments…Jan 17Jan 17
Account Takeover via IDOR in GraphQL Invitation FlowHey Hackers, I am Parth Narula. A penetration tester, bug hunter, red teamer and overall a security researcher. I live for those moments…Jan 5A response icon3Jan 5A response icon3
Horizontal Privilege Escalation via IDOR: Viewing, Editing and DeletingHey Hackers, I am Parth Narula. A penetration tester, bug hunter, red teamer and overall a security researcher. I live for those moments…Dec 25, 2025A response icon2Dec 25, 2025A response icon2
IDOR Privilege Escalation: Deleting Protected AccountsHey Hackers, I am Parth Narula. A penetration tester, bug hunter, red teamer and overall a security researcher. I live for those moments…Dec 12, 2025A response icon1Dec 12, 2025A response icon1
Double-Door IDOR Exposing 85k+ EmailsHey Hackers, I am Parth Narula. A penetration tester, bug hunter, red teamer and overall a security researcher. I live for those moments…Dec 6, 2025A response icon1Dec 6, 2025A response icon1
Exploiting an IDOR to Claim Unavailable Free GiftsHey Hackers, I am Parth Narula. A penetration tester, bug hunter, red teamer and overall a security researcher. I live for those moments…Nov 25, 2025A response icon1Nov 25, 2025A response icon1