The Brew Store
Created by admin · 3 weeks, 3 days ago
Description
Specialty coffee e-commerce store with subscriptions, support desk, invoices and a customer API. A realistic IDOR playground: identifiers are everywhere and almost none of them are checked.
Scope
All functionality on tbs.thebugbountyroom.com is in scope, including:
- Order tracking pages and their identifiers (order numbers, receipt references, invoices)
- The customer API under /api/v1/* (orders, profile export, addresses)
- Subscription management links and cancel flows
- The support centre (tickets, replies, staff notes)
Focus areas: broken object-level authorization (BOLA/IDOR) across every endpoint that takes an identifier — numeric IDs, UUIDs, tokens, encoded references and write operations. Chaining findings is encouraged.
Out of Scope
Automated scanners, DoS/traffic flooding, actually charging cards (demo card data), and phishing other hunters. The demo accounts shown on the login page are shared test accounts.
Recent Submissions
Submit ReportNo reports yet. Be the first to submit!