Learn to find this bug
This bug paid $140 on YesWeHack.
Create your account and practice real bugs that got paid. Download the environment, find it and learn the exact technique — your path to your first bounty.
- hunters training
- 650
- labs from real reports
- 50
- completions
- 380
- in bounties practiced
- $200,000
hunters training
labs from real reports
completions
in bounties practiced
40 flags captured this week
Access to all labs · no commitment · cancel anytime
Hunters who solved it· 8
Achievement you'll earn
Solve this lab to unlock this shareable achievement
BBLABS.ESLab Solved
Medium$140
// achievement_unlocked
Open Redirect con Referer Check + Domain Bypass (@)
Open Redirect
Aug 2026
solved_by@gorkaMember since Mar 2026
bblabs.es// real bug bounty practice
Community writeups
Cadena de ataque
1. Explorar la app → descubrir posts patrocinados con tracking URLs
2. Analizar: /ads/tr?ci=X&e=sk&tu=https://cdn.snapvibe.com/...
3. Probar sin Referer → 401
4. Probar con Referer válido → 302 (funciona)
5. Probar tu=https://evil.com → 400 (dominio no whitelisted)
6. Bypass dominio: tu=http://cdn.snapvibe.com@localhost:9999 → 302!
7. Publicar link completo como comentario en una foto
8. Bot clicka → sigue redirect → llega a attacker con X-Secret-Token
9. Flag: ......
Credenciales
| Usuario | Contraseña | Rol |
|---|---|---|
| sarah_photo | password123 | user |
| mike_design | password123 | user |
| elena_travel | password123 | user |
Despliegue
./autodeploy.sh
# o: docker compose up --build
# Acceder: http://localhost:1000