I turned Claude Code loose on two live HackerOne programs and let it do the recon for me — mapping attack surface, reading scope, and hunting IDOR/BOLA and business-logic bugs while I narrate what’s happening.
Think of it like a co-pilot doing the boring grid-search of the map while I steer: I feed it the target and the rules of engagement, it enumerates the API surface, flags the high-value targets (multi-tenant isolation keys, session tokens, wallet endpoints), and even drives the browser to capture the exact request/response shapes I’d need to build an attack script.
What’s in this session:
– Reading and interpreting real HackerOne scope + ineligible-findings rules
– Claude Code’s recon on Kaltura’s KMC — exposed api_v3 REST API, partner_id cross-tenant IDOR/BOLA, KS session tokens, admin endpoints
– Why I bailed on the inDrive program (it wanted a credit card before install)
– A live pivot to Agoda when the Kaltura sign-up turned into a headache
– Mapping AgodaCash / cashback wallet endpoints and member identifiers
– Understanding what’s actually payable: systematic booking-token retrieval, cashback manipulation, multi-field enumeration
– Watching the agent find a member-ID leak, then capture the pre-book/price-validation API right inside DevTools to reverse the request shape
This is a recon-only walkthrough — no exploitation, all activity inside authorized HackerOne program scope. Meant to be educational: how AI-assisted recon actually looks in practice, where it shines, and where a human still has to make the calls.
Chapters
00: 00 Intro — letting an AI agent run my recon
00: 34 Reading the Kaltura scope & registration task
01: 09 Program guidelines and out-of-scope rules
01: 59 Claude Code’s Kaltura findings (exposed api_v3, partner_id IDOR, KS tokens)
03: 08 Why I skipped the inDrive program (mobile app + credit-card wall)
04: 47 Registering the demo account + broken sign-up bugs
06: 45 Kaltura VPaaS free-trial form / developer portal
07: 12 Pivot to Agoda — recon on cashback rewards
09: 27 Mapping Agoda’s wallet endpoints & member identifiers
10: 10 Agoda’s rules: XSS banned, risk-accepted IDORs
11: 24 Booking-token IDOR — eligible vs. ineligible
12: 26 In-scope: AgodaCash, cashback wallet & business logic
13: 55 Search URL leaks my member ID (prime IDOR target)
14: 51 Claude books & cancels a real room mid-recon
15: 55 Capturing the price-validation API in DevTools
18: 05 Outro — stay vigilant, happy hacking
#bugbounty #hackerone #cybersecurity #ethicalhacking #IDOR #AI #claudecode #infosec #pentesting #reconnaissance
━━━━━━━━━━
For educational purposes only. All testing shown was performed against targets explicitly in scope on their respective HackerOne bug bounty programs. Never test systems you don’t have permission to test.