
Cool Pentest Findings with Quailu
"Cool Pentest Findings with Quailu" is a podcast that uncovers the most creative, high-impact vulnerabilities reported in bug bounty platforms and penetration testing projects. Hosted by cybersecurity expert Amin Malekpour, this show breaks down real-world penetration testing findings, explaining how they happened, why they matter, and what we can learn from them. Whether you're a penetration tester, developer, or just curious about ethical hacking, this podcast provides practical insights in a clear, engaging format. New episodes drop fortnightly! Stay curious, hack ethically, and keep learning with us.
π Follow & Connect β LinkedIn, YouTube, Twitter, Instagram
π© Submit Your Pentest Findings β https://forms.gle/7pPwjdaWnGYpQcA6A
π§ Feedback? Email Us β podcast@quailu.com.au
Cool Pentest Findings with Quailu
Account Takeover via IDOR Chains, CSRF in Security Questions Leading to Account Takeover & Privilege Escalation by Token Manipulation
In this episode of Cool Pentest Findings with Quailu, we break down three powerful security flaws that lead to account takeovers and privilege escalation.
π Whatβs Inside:
β
Account takeover via IDOR chaining β How combining two IDOR vulnerabilities led to full control over user accounts.
β
CSRF in security questions leading to account takeover β A simple CSRF flaw that allowed attackers to reset victim passwords.
β
Privilege escalation by token manipulation β How weak authorization checks enabled attackers to escalate their privileges.
Each finding demonstrates how small misconfigurations can snowball into major security risksβand what you can do to prevent them.
Have a cool pentest finding to share? Submit your discoveries via the Google Form in the episode description! Also, follow, rate, and review to support the podcast.
π Stay curious, hack ethically, and keep learning!
π Follow & Connect β LinkedIn, YouTube, Twitter, Instagram
π© Submit Your Pentest Findings β Google Form link
π§ Feedback? Email Us β podcast@quailu.com.au
π Podcast Website β Website Link