AboutResearchStatsSCAMMethodStackContact
Independent security research2026

01 / PORTFOLIO

Break the
expected.

I research web applications and APIs to uncover weaknesses in authentication, access control and business logic.

WEB / API / AUTH / LOGICRESPONSIBLE DISCLOSURE
01EX
research@1exbug

$ whoami

1exbug — security researcher

$ scope

web · api · auth · access-control · logic

$ mode

● responsible disclosure

$ hunt --mode=methodical

▋
29documented findings
11research targets
03core focus areas
02public write-ups
02A
SECURITY STATS

Research at a glance.

0129documented findings
0211research targets
03200K ₽largest listed payout
0402public write-ups
02
ABOUT

Think like the application.

Security research is less about throwing payloads at a target and more about understanding what the application assumes is true. I map those assumptions, challenge them and turn unexpected behavior into reproducible evidence.

01

Observe

Map endpoints, roles, tokens, state transitions and trust boundaries.

02

Challenge

Test what happens when the expected sequence, identity or state changes.

03

Prove

Reduce the behavior to a clean, repeatable proof and document it responsibly.

03
RESEARCH

Selected findings.

01xSLOTSDOCUMENTED
01

Authentication & account logic

Authentication, session and account-control issues documented across the application.

No rate limit2FASession IDORPassword reset
Выплата200 000 ₽
Read write-up↗
ON-XDOCUMENTED
02

Authorization & business logic

KYC, payout, balance, race-condition and WebSocket access-control findings.

KYCIDORRaceWebSocket
Выплата75 000 ₽
Read write-up↗
ZOOMARESPONSE RECEIVED
03

Responsible disclosure

Race conditions, IDOR, XSS and token-exposure issues reported through a responsible disclosure channel.

RaceIDORXSSToken

Zooma подтвердила XSS через winnerName в розыгрышах, а также Stored XSS в Classic1v1, GiveAway, RainDrop и Tournaments Feed и сообщила о готовности выплатить 35 000 ₽.

Статус: Ответ получен

Награда: 35 000 ₽

Разрешение на исследование: получено 23.09.2026

Bug bounty программа: отсутствует, выплаты в индивидуальном порядке

CASHERREPORTED
04

Security findings

Production credential exposure, client-side authentication key exposure and several access-control and injection points reported to Casher.

CredentialsAuth KeyBOLAMQTTXSS

Статус: Report sent to Casher

Exposed Production Credentials: Production MQTT/WebSocket credentials found in a public JavaScript bundle.

Client-Side Authentication Key Exposure: signature_hash_key is passed to the client and used to form x-signature authentication requests.

Potential IDOR / BOLA: API endpoints using user_id and transaction_id require server-side authorization checks.

Potential MQTT Cross-Account Access: User-specific MQTT topics require ACL validation against access to other users' data.

Potential XSS Sink: innerHTML is used when rendering notification content; exploitability requires additional verification.

VODKA CASINOVERIFIED
05

WebSocket access control

Исследование WebSocket / Centrifugo. Обнаружена проблема авторизации персональных каналов.

WebSocketBroken Access ControlCentrifugo
Open research↗
CABURAREPORTED
06

Security findings

Статический и динамический аудит клиентской части cabura. Обнаружены критические проблемы контроля доступа, обхода антибот-защиты и слабой валидации финансовых операций.

BOLAIDORAnti-BotWebSocketCSRFSSRFBusiness Logic

Статус: Отчёт отправлен в поддержку Cabura

Находки: 6 findings

DRAGON MONEYREPORTED
07

Dragon Money — Bug Bounty Report

Полный отчёт по 7 уязвимостям клиентской части Dragon Money (drgn70.casino): XSS, криптографический ключ, fingerprint, роли и JWT.

XSSCWE-79CWE-321Critical

Статус: Отчёт отправлен в security@drag0n.team

Находки: 7 уязвимостей

04A
TIMELINE

Research history.

Zooma CasinoResearch permission received.
MoneyX CasinoResponsible disclosure sent.
CasherSecurity findings reported.
04
SCAM WATCH

Unresolved disclosures.

!

This table records unresolved disclosure communication only. A SCAM label is not a verified accusation; entries are based on documented contact status and are subject to update.

#TargetStatus
01MoneyX Casinono response · 4 days!
Last contact: 26.09.2026 Basis: responsible disclosure sent; no reply received Classification: unverified / unresolved
02CABURAcommunication unresolved!
Last contact: 30.09.2026 Basis: According to the researcher, the support operator/admin communicated in a trolling / dismissive manner, prolonged the discussion and did not seriously address any of the reported points. Classification: unverified / unresolved communication issue
05A
VULNERABILITY MATRIX

What gets tested.

01AuthenticationAUTH
02IDOR / BOLAACL
03XSSXSS
04Race ConditionsRACE
05WebSocketsWS
06Session SecuritySESS
05B
RESEARCH CONSOLE

Talk to the terminal.

1exbug@research:~

1exbug@research:~$ help

about · findings · targets · payouts · contact · status · clear

1exbug@research:~$
05
TARGETS

Research surface.

#TargetState
011xSlotsdocumented↗ 02ON-X Casinodocumented↗
03Zooma Casinoresponse received✓
04BC.GAMEdisclosure•
05JetTon Casinodisclosure•
06Shuffledisclosure•
07Cloudbetdisclosure•
08Casherreport sent•
09Vodka Casinoverified research✓
10CABURAreport sent↗
11Dragon Moneyreport sent↗
06A
BOUNTY HISTORY

Disclosure outcomes.

TargetIssueAmountStatus
Zooma CasinoXSS / winnerName35 000 ₽offered
1xSlotsmultiple findings200 000 ₽payout recorded
ON-X Casinomultiple findings75 000 ₽payout recorded
07
METHOD

Map. Model. Break. Prove.

01

Map

Routes, APIs, parameters, roles, tokens and application state.

02

Model

Trust boundaries, assumptions and what the server actually verifies.

03

Break

Authorization, validation, concurrency, state and business logic.

04

Prove

Minimal reproduction, evidence, impact and responsible disclosure.

08
STACK

Tools & focus.

Web SecurityAPI TestingAuthenticationAuthorizationIDORBusiness LogicRace ConditionsWebSocketsXSSSession SecurityBurp SuiteDevToolsHTTPJavaScriptLinux
CONTACT

Let's talk security.

Responsible disclosure, research collaboration or a technical question — choose a channel.

Email copied
REPORT 06 / CABURA

CABURA — Security findings