Uploaded May 2026 | Updated September 2026, 1 day ago
Three triaged bugs across three different platforms. A report generator that leaked private creator revenue because the developer validated the read path and forgot the action path. A real-time cursor color that exfiltrated victim IPs through a CSS background-image trick. A Python sandbox in a spreadsheet platform that turned out to be a label, not a boundary. I found every one of them one hour before I was ready to walk.
π― This video is sponsored by OctoBrowser
π octobrowser.net
Promo code: AMRSEC (4 days free on the starter subscription)
π― Get My Full Caido For Hackers Course: hhub.io/AMRCAIDO
π‘ Support AmrSec on Patreon:
patreon.com/AmrSec
π₯ Join Our Community:
Discord: discord.gg/nxHKyJTy3h
π Resources
Video Article: amrelsagaei.com/3-bugs-i-found-one-hour-before-giving-up
β Become a Channel Member:
youtube.com/@AmrSecOfficial/join
β οΈ Disclaimer
This channel is for educational purposes only. The goal is to teach cybersecurity, ethical hacking, and red team/blue team skills through real tools, techniques, and experience. Always hack ethically. π«‘
π Timestamps
00:00 Introduction
00:55 Hold on...
02:24 1st Bug: The Report That Wasn't Mine
10:58 2nd Bug: The Cursor That Called Home
20:11 3rd Bug: The Formula That Read the Server
29:30 Conclusion
Follow AmrSec
LinkedIn: linkedin.com/in/amrelsagaei
Twitter/X: twitter.com/amrelsagaei
Instagram: instagram.com/amrelsagaei
#BugBounty #IDOR #CSSInjection #SandboxEscape #WebSecurity #EthicalHacking #AmrSec
Three triaged bugs across three different platforms. A report generator that leaked private creator revenue because the developer validated the read path and forgot the action path. A real-time cursor color that exfiltrated victim IPs through a CSS background-image trick. A Python sandbox in a spreadsheet platform that turned out to be a label, not a boundary. I found every one of them one hour before I was ready to walk.
π― This video is sponsored by OctoBrowser
π octobrowser.net
Promo code: AMRSEC (4 days free on the starter subscription)
π― Get My Full Caido For Hackers Course: hhub.io/AMRCAIDO
π‘ Support AmrSec on Patreon:
patreon.com/AmrSec
π₯ Join Our Community:
Discord: discord.gg/nxHKyJTy3h
π Resources
Video Article: amrelsagaei.com/3-bugs-i-found-one-hour-before-giving-up
β Become a Channel Member:
youtube.com/@AmrSecOfficial/join
β οΈ Disclaimer
This channel is for educational purposes only. The goal is to teach cybersecurity, ethical hacking, and red team/blue team skills through real tools, techniques, and experience. Always hack ethically. π«‘
π Timestamps
00:00 Introduction
00:55 Hold on...
02:24 1st Bug: The Report That Wasn't Mine
10:58 2nd Bug: The Cursor That Called Home
20:11 3rd Bug: The Formula That Read the Server
29:30 Conclusion
Follow AmrSec
LinkedIn: linkedin.com/in/amrelsagaei
Twitter/X: twitter.com/amrelsagaei
Instagram: instagram.com/amrelsagaei
#BugBounty #IDOR #CSSInjection #SandboxEscape #WebSecurity #EthicalHacking #AmrSec










