Gerben Javado Security & Bug Bounty Stories

Recon Android apps to widen scope

Even though it is "common" knowledge that mobile apps are undertested, I often talk to people that have been hunting bugs for a while but don't include mobile...

Manual SQL injection discovery tips

According to bugbountyforum.com's AMA format one of the most popular questions is How do you test for Server Side vulnerabilities such as SQLi?. Up until recently I was struggling...

The race to the top of a bug bounty program

Recently I had unusual success on a public program on HackerOne. Here is my story on how I approached this program, what I found and how I found it. July...

Discovering hidden endpoints using LinkFinder

For those who don't know me I am Gerben Janssen van Doorn (online known as: "gerben_javado"). Im a 21-year-old bug bounty hunter mainly working on HackerOne and...