Client Engagement · Public Program

Coordinated disclosure — live multi-tenant consumer marketplace

Independent, authorized security research against a high-traffic marketplace through its public bug-bounty program — recon to responsible disclosure.

Client / target: Classified — public bug-bounty program (identity withheld)
Engagement: Authorized independent research & coordinated disclosure (HackerOne)
Outcome: A valid vulnerability identified and responsibly disclosed; triaged as an independent rediscovery of a known issue.
ReconAPI surfaceSSRFAccess controlCoordinated disclosure
Conducted strictly within the program's published scope and safe-harbor rules. All findings were reported privately through the official channel. No exploit detail, internal identifier, or program-confidential information is disclosed here.

Approach

We treated a live, real-user marketplace the way an attacker would — mapping the real attack surface before touching anything, then testing the high-value trust boundaries by hand.

Outcome

We identified a valid vulnerability and disclosed it responsibly through the program's official channel. It was triaged as a duplicate — an independent rediscovery of an issue the program was already tracking. That outcome still demonstrates the core of the work: finding a real, reportable flaw in a large, actively-defended production system through disciplined manual testing, and handling it through correct coordinated-disclosure process.

Why it matters to a client

This is the same workflow applied to a paid engagement — recon, surface mapping, manual testing of cross-tenant authorization and SSRF, and a clean, privately-reported finding. The marketplace was a hardened, high-traffic target; the methodology is exactly what a startup or SMB gets pointed at their own product.

← Back to case studies