We are getting close to releasing BugBountyHunter v2 which will introduce a brand new website, including member platforms, new features, challenges, guides, videos, and the long awaited zseano methodology v2. Right now, all of the content on this website is considered out-dated, however our members section continues to operate for members.
Stay tuned for updates coming soon!
FirstBlood-#110 — Information Leak leads to full backend access
This issue was discovered on FirstBlood v1
On 2021-05-10, jonlaing Level 2 reported:
After running a google search on firstbloodhackers.com I came across the Reddit page which has post by someone revealing their Invitation Code.
https://www.reddit.com/r/BugBountyHunter/comments/n4xzw1/firstbloodhackerscom_doctor_registration/

From there we can register by entering our name and the invite code and it gives us an account.

P2 High
Parameter:
Payload:
FirstBlood ID: 15
Vulnerability Type: Auth issues
A doctors invite code is leaked on the internet which if used grants anyone access to the doctor portal. The invite code should expire after use.