Sept. 2, 2023, 12:45 p.m. | Gowthamaraj Rajendran (@fuffsec)

System Weakness - Medium systemweakness.com

Introduction

Imagine casually browsing the web, only to stumble upon a major security flaw on a United Nations (UN) website. Seems like the stuff of fiction, right? Well, that’s precisely what happened to me, and today, I’m sharing my exhilarating journey of how I found a “leaked Google Maps API key” on a UN site and ended up in their Hall of Fame. So, buckle up and enjoy this rollercoaster ride of discovery, vulnerability reporting, and recognition!

The Discovery

It …

bug bounty bug-bounty-tips bug-bounty-writeup bugs hall-of-fame

Security Analyst

@ Northwestern Memorial Healthcare | Chicago, IL, United States

GRC Analyst

@ Richemont | Shelton, CT, US

Security Specialist

@ Peraton | Government Site, MD, United States

Information Assurance Security Specialist (IASS)

@ OBXtek Inc. | United States

Cyber Security Technology Analyst

@ Airbus | Bengaluru (Airbus)

Vice President, Cyber Operations Engineer

@ BlackRock | LO9-London - Drapers Gardens