Approach
We treated a live, real-user marketplace the way an attacker would — mapping the real attack surface before touching anything, then testing the high-value trust boundaries by hand.
- Reconnaissance: subdomain enumeration from certificate transparency, service and tech-stack fingerprinting, and attack-surface mapping.
- API surface: enumerated and mapped the versioned API and its authentication paths, looking for broken object- and function-level authorization across tenants.
- Server-Side Request Forgery: tested URL-ingesting functionality (including an image-proxy feature) with a full bypass ladder — private-IP ranges, IPv6 loopback, decimal-encoded addresses, and redirect-to-metadata chains.
- Every candidate finding verified with a positive control before reporting — no scanner-only claims.
Outcome
We identified a valid vulnerability and disclosed it responsibly through the program's official channel. It was triaged as a duplicate — an independent rediscovery of an issue the program was already tracking. That outcome still demonstrates the core of the work: finding a real, reportable flaw in a large, actively-defended production system through disciplined manual testing, and handling it through correct coordinated-disclosure process.
Why it matters to a client
This is the same workflow applied to a paid engagement — recon, surface mapping, manual testing of cross-tenant authorization and SSRF, and a clean, privately-reported finding. The marketplace was a hardened, high-traffic target; the methodology is exactly what a startup or SMB gets pointed at their own product.
← Back to case studies