The Invite That Lied: A Business Logic Flaw Hidden Behind LG’s Walls
作者通过使用工具ShrewdEye发现LG的一个活跃子域名,并从中寻找潜在漏洞,目标是获得LG的感谢信而非漏洞奖金。 2025-7-12 13:37:21 Author: infosecwriteups.com(查看原文) 阅读量:8 收藏

LordofHeaven

I wasn’t chasing a bounty this time.
This time, the thrill was different — I wanted to earn a Letter of Appreciation from LG.

Not a bug bounty. Not a write-up trophy. Just a clean, solid find. Something they’d remember.

Because when you’re dealing with a brand like LG — where polish meets production — you know there’s more beneath the surface.

So, I did what I do best: opened my recon toolkit, fired up some intuition, and started hunting for cracks in the logic.

My recon game started with a weapon I absolutely love: ShrewdEye.

It pulls out subdomains like magic — raw, downloadable, no UI fluff.

wget https://shrewdeye.app/domains/<domain_name>.txt

The file dropped, and with it came hundreds of subdomains — some dormant, some suspicious, and a few… just alive enough to be dangerous.

I filtered down the list for targets with 200 OK responses.

And then I saw it.

A subdomain I won’t name here (you know the drill), but let’s just call it:

xyz.redacted.lg.com

It wasn’t just alive.
It was buzzing — login flows, invitation systems, beta-looking dashboards just like every other normal web-app

The kind of place where real bugs hide in real logic.


文章来源: https://infosecwriteups.com/the-invite-that-lied-a-business-logic-flaw-hidden-behind-lgs-walls-a49cca506294?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh