01 / PORTFOLIO
Break the
expected.
I research web applications and APIs to uncover weaknesses in authentication, access control and business logic.
$ whoami
1exbug — security researcher
$ scope
web · api · auth · access-control · logic
$ mode
● responsible disclosure
$ hunt --mode=methodical
▋Research at a glance.
Think like the application.
Security research is less about throwing payloads at a target and more about understanding what the application assumes is true. I map those assumptions, challenge them and turn unexpected behavior into reproducible evidence.
Observe
Map endpoints, roles, tokens, state transitions and trust boundaries.
Challenge
Test what happens when the expected sequence, identity or state changes.
Prove
Reduce the behavior to a clean, repeatable proof and document it responsibly.
Selected findings.
Authentication & account logic
Authentication, session and account-control issues documented across the application.
Authorization & business logic
KYC, payout, balance, race-condition and WebSocket access-control findings.
Responsible disclosure
Race conditions, IDOR, XSS and token-exposure issues reported through a responsible disclosure channel.
Zooma подтвердила XSS через winnerName в розыгрышах, а также Stored XSS в Classic1v1, GiveAway, RainDrop и Tournaments Feed и сообщила о готовности выплатить 35 000 ₽.
Статус: Ответ получен
Награда: 35 000 ₽
Разрешение на исследование: получено 23.09.2026
Bug bounty программа: отсутствует, выплаты в индивидуальном порядке
Security findings
Production credential exposure, client-side authentication key exposure and several access-control and injection points reported to Casher.
Статус: Report sent to Casher
Exposed Production Credentials: Production MQTT/WebSocket credentials found in a public JavaScript bundle.
Client-Side Authentication Key Exposure: signature_hash_key is passed to the client and used to form x-signature authentication requests.
Potential IDOR / BOLA: API endpoints using user_id and transaction_id require server-side authorization checks.
Potential MQTT Cross-Account Access: User-specific MQTT topics require ACL validation against access to other users' data.
Potential XSS Sink: innerHTML is used when rendering notification content; exploitability requires additional verification.
WebSocket access control
Исследование WebSocket / Centrifugo. Обнаружена проблема авторизации персональных каналов.
Open research↗Security findings
Статический и динамический аудит клиентской части cabura. Обнаружены критические проблемы контроля доступа, обхода антибот-защиты и слабой валидации финансовых операций.
Статус: Отчёт отправлен в поддержку Cabura
Находки: 6 findings
Dragon Money — Bug Bounty Report
Полный отчёт по 7 уязвимостям клиентской части Dragon Money (drgn70.casino): XSS, криптографический ключ, fingerprint, роли и JWT.
Статус: Отчёт отправлен в security@drag0n.team
Находки: 7 уязвимостей
Research history.
Unresolved disclosures.
This table records unresolved disclosure communication only. A SCAM label is not a verified accusation; entries are based on documented contact status and are subject to update.
What gets tested.
Talk to the terminal.
1exbug@research:~$ help
about · findings · targets · payouts · contact · status · clear
Research surface.
Disclosure outcomes.
Map. Model. Break. Prove.
Map
Routes, APIs, parameters, roles, tokens and application state.
Model
Trust boundaries, assumptions and what the server actually verifies.
Break
Authorization, validation, concurrency, state and business logic.
Prove
Minimal reproduction, evidence, impact and responsible disclosure.