One Link, One Report, One Four-Digit Bounty
infosecwriteups.com·4d
🌐WARC Forensics
Preview
Report Post

2 min readOct 17, 2025

Sometimes in bug bounty hunting, simple recon can lead to big results. Recently, during GitHub reconnaissance, I found an issue that turned into a valid report and earned me a four-digit bounty.

The Discovery

While checking repositories linked to employees of my target company, I came across a repo that contained a link. When I opened it, the link led to an active sheet.

The sheet exposed:

  • Employee IDs and details
  • An attendance form still being used daily
  • Vendor-related information and other data

This wasn’t just old or leftover data — it was live and could have been misused.

The Report

Get Narayanan M’s stories in your inbox

Join Medium for free to get updates from this writer.

I documented the finding careful…

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help