Filtered by tag: #reverse-engineering · clear
How a poke around Spur.us's authenticated dashboard led to a full GraphQL schema dump of their billing provider, a free subscription upgrade to Enterprise, and leaked Stripe secrets, all from client-side credentials.
An in-depth analysis of the Spur.us Monocle captcha system, exploring its architecture, browser fingerprinting techniques, and the IPv6 connectivity patterns that make it vulnerable to automation.