<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/breaking-and-reporting-bugs-the-story-behind-my-comet-and-black-hole-wins-on-yeswehack-x1arxnwcr" -->

---
title: Breaking and Reporting Bugs: The Story Behind My Comet...
description: A bug bounty hunter shares findings from a single YesWeHack program where 10 valid vulnerabilities were discovered, earning both the Comet and Black Hole...
canonical: https://daily.dev/posts/breaking-and-reporting-bugs-the-story-behind-my-comet-and-black-hole-wins-on-yeswehack-x1arxnwcr
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Breaking and Reporting Bugs: The Story Behind My Comet and Black Hole Wins on YesWeHack | daily.dev
og:description: A bug bounty hunter shares findings from a single YesWeHack program where 10 valid vulnerabilities were discovered, earning both the Comet and Black Hole...
og:url: https://daily.dev/posts/breaking-and-reporting-bugs-the-story-behind-my-comet-and-black-hole-wins-on-yeswehack-x1arxnwcr
og:image: https://api.daily.dev/og/posts/X1arxnwCr.png
og:image:alt: Breaking and Reporting Bugs: The Story Behind My Comet and Black Hole Wins on YesWeHack
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Breaking and Reporting Bugs: The Story Behind My Comet and Black Hole Wins on YesWeHack

**[InfoSec Write-ups](https://daily.dev/sources/infosecwriteups)** · 6 min read · 0 upvotes · 0 comments

## Summary

A bug bounty hunter shares findings from a single YesWeHack program where 10 valid vulnerabilities were discovered, earning both the Comet and Black Hole badges. The write-up covers five key vulnerabilities: a broken access control flaw enabling enterprise account takeover by swapping an enterprise_id in a POST request; an unauthenticated MongoDB instance on port 27017 exposing over 155,000 production records; a stored XSS in an establishment name field enabling session cookie theft and account takeover; an unauthenticated API endpoint leaking user feedback with PII; and an IDOR in an AI analysis download endpoint allowing access to other organizations' documents. Each finding is explained with request examples and impact analysis.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://infosecwriteups.com/breaking-and-reporting-bugs-the-story-behind-my-comet-and-black-hole-wins-on-yeswehack-15d5f0d39d50>

## Similar posts on daily.dev

- [How I Found 2 Bugs on BBC’s Subdomains and Made It Into Their Hall of Fame](https://daily.dev/posts/how-i-found-2-bugs-on-bbc-s-subdomains-and-made-it-into-their-hall-of-fame-z89xc1jth) · InfoSec Write-ups · 1 upvotes · 0 comments
- [A Hacker’s Journey to NASA’s Hall of Fame](https://daily.dev/posts/a-hacker-s-journey-to-nasa-s-hall-of-fame-yttnufba0) · InfoSec Write-ups · 0 upvotes · 0 comments
- [How I Became the 4th Top Bug Bounty Researcher on Comolho: My Journey](https://daily.dev/posts/how-i-became-the-4th-top-bug-bounty-researcher-on-comolho-my-journey-hdzr5orvl) · InfoSec Write-ups · 5 upvotes · 1 comments
- [From Zero Reports to My First Hall of Fame](https://daily.dev/posts/from-zero-reports-to-my-first-hall-of-fame-lxbtw0kqp) · InfoSec Write-ups · 0 upvotes · 0 comments
- [Rejected but Rewarded — What a GraphQL Misconfiguration Taught Me About Bug Bounty Triage.](https://daily.dev/posts/rejected-but-rewarded-what-a-graphql-misconfiguration-taught-me-about-bug-bounty-triage--hikmucc04) · InfoSec Write-ups · 0 upvotes · 0 comments

---

[View this post on daily.dev](https://daily.dev/posts/breaking-and-reporting-bugs-the-story-behind-my-comet-and-black-hole-wins-on-yeswehack-x1arxnwcr)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Breaking and Reporting Bugs: The Story Behind My Comet and Black Hole Wins on YesWeHack","url":"https://daily.dev/posts/breaking-and-reporting-bugs-the-story-behind-my-comet-and-black-hole-wins-on-yeswehack-x1arxnwcr","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/breaking-and-reporting-bugs-the-story-behind-my-comet-and-black-hole-wins-on-yeswehack-x1arxnwcr"},"datePublished":"2026-03-16T06:12:56.849Z","dateModified":"2026-03-16T06:13:22.960Z","description":"A bug bounty hunter shares findings from a single YesWeHack program where 10 valid vulnerabilities were discovered, earning both the Comet and Black Hole...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f260cf0c5ec9956a671de7b9eb537a4b?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f260cf0c5ec9956a671de7b9eb537a4b?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"InfoSec Write-ups","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"InfoSec Write-ups","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/f0dc21b5bbfd46fda36f7b4b53dd1705","url":"https://daily.dev/sources/infosecwriteups"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/breaking-and-reporting-bugs-the-story-behind-my-comet-and-black-hole-wins-on-yeswehack-x1arxnwcr","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"InfoSec Write-ups","item":"https://daily.dev/sources/infosecwriteups"},{"@type":"ListItem","position":3,"name":"Breaking and Reporting Bugs: The Story Behind My Comet and Black Hole Wins on YesWeHack"}]}
```

