Portfolio
Padmesh P S MMXXVI
Field notes

Seventeen

breach reports.
· · ·

Vulnerabilities I found in production, on real platforms — written as field notes, not reports.

⌄ scroll to begin
Preface

Seventeen vulnerabilities. Five production platforms.

This is a reader, not a report. The findings here were collected across five production platforms — a state transport corporation serving fifty thousand passengers a day, a government college ERP, a managed cloud provider, a food delivery giant, and a ride-hailing company operating at scale.

Some are catastrophic. Some are chains — individually low severity, collectively account takeover. A few are the kind of thing you read twice before you believe it shipped: a CAPTCHA endpoint that returned the answer, a gift card hash key that was literally 1234123412341234, a state-wide platform that went offline from a single unauthenticated SQL probe.

Names are real. Payloads are sanitized. Severities are my own assessment, noted against CWE and CVSS where meaningful. Where testing caused measurable platform impact, it is stated. All work was performed under authorization, disclosed program scope, or responsible disclosure.

17
Findings
5
Targets
3
Critical
1
Write-up
· · ·

The work is the disclosure.

Every finding in this reader was reported to its respective vendor through the channel they advertised — a bug-bounty program, a security@ address, or in two cases, a written assessment with prior authorization.

One of the seventeen became a long-form write-up on Medium. The rest live here.