// Archive

Posts & Writeups

Technical research, vulnerability analyses, and security notes.

Web SecurityAppsecAPI SecurityBypass

Never Trust the Client: How I Manipulated the Leaderboard of an App with Anti-Fraud Logic

A technical dive into bypassing client-side anti-fraud checks, tampering with WebSocket/HTTP payloads, and why backend validation is non-negotiable.

Read in:[ EN ][ PT ]