Tagged articles

Authorization Header

3 articles · Page 1 of 1
Black & White Path
Black & White Path
Jul 8, 2026 · Information Security

How I Earned $23,000 by Exploiting JWT Realm and File Overwrite Vulnerabilities

The article details a step‑by‑step exploitation chain against a site using JWT authentication and an upload endpoint, showing how modifying the JWT realm, removing the Bearer keyword, and abusing Amazon S3/CloudFront default settings enabled arbitrary file overwrite and yielded a total $23,000 bounty.

Authorization HeaderCloudFrontFile Overwrite
0 likes · 7 min read
How I Earned $23,000 by Exploiting JWT Realm and File Overwrite Vulnerabilities
Black & White Path
Black & White Path
Jun 8, 2026 · Information Security

How a Single Authorization Header Bypassed Authentication and Earned a $3,000 Bounty

Security researcher ALR discovered that a web application only checks for the presence of the Authorization header, allowing any request with "Authorization: Basic"—even without credentials—to access around 50 API endpoints, leading to a critical authentication bypass and a $3,000 bounty.

Authentication BypassAuthorization HeaderHTTP Basic Authentication
0 likes · 5 min read
How a Single Authorization Header Bypassed Authentication and Earned a $3,000 Bounty
JavaEdge
JavaEdge
Aug 20, 2023 · Information Security

Cookie vs Authorization Header: Which Token Storage Method Is Safer?

This article compares storing authentication tokens in cookies versus the Authorization header, outlining each method's implementation, advantages, drawbacks, security implications such as XSS and CSRF risks, cross‑domain considerations, and compliance with authentication standards.

AuthenticationAuthorization HeaderToken Storage
0 likes · 5 min read
Cookie vs Authorization Header: Which Token Storage Method Is Safer?