frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

I bypassed AWS API Gateway auth with a trailing slash. Got $12K bounty

https://theguptalog.blogspot.com/2026/04/i-bypassed-aws-api-gateway-auth-with.html
24•tjek•48m ago

Comments

A_Duck•32m ago
$1 removing the slash, $11,999 knowing where to remove the slash from
dizhn•16m ago
At that rate I would remove it from everywhere.
throw1234567891•5m ago
But do you know where they all are
redrove•29m ago
Don’t vibe code your auth path folks.
darkwater•10m ago
Otherwise a security research will vibe-code and exploit and slop out a blog post about it.
IshKebab•28m ago
You could have written this up without using AI and I would have hated it less.
tedk-42•27m ago
Hmmm 12K seems like a bit much, even if it's fintech.

They also didn't mention the company.

The title feels clickbaity as it's not specific to AWS API gateway and instead, the implementation of it.

And who hosts on blogspot...

savolai•15m ago
It's not really fair to criticise hosting choice, but this lead me down a rabbit hole.

Noticed that non-responsive blog layouts are rare these days. Most are from blogspot. So I took a look and realized that blogger nowadays actually supports responsive layouts, but apparently... they are not popular?

https://blogger.googleblog.com/2017/03/share-your-unique-sty...

Quarrelsome•15m ago
got any more criticisms, font choice, perhaps there's some duplication in their css?

I think 12k could be fine given how much it might have cost them if nobody had noticed?

utf_8x•13m ago
Considering it let them do an unauthorized wire transfer from a system account, 12k seems pretty reasonable.
treszkai•9m ago
Yes, it and the other three posts sound positively AI written. The first post on the blog is how OP uploaded a backdoored dataset to HuggingFace and left it there for 6 months – whether made up or not, it doesn't sound great.
mapcars•26m ago
Interesting story showing how complex todays tech is, and your whole security plan can be compromised by regexp matching rules.
sammy2255•25m ago
Did you Bypass AWS API Gateway.. or did you bypass it for a company who had their AWS API Gateway misconfigured?
stuartjohnson12•20m ago
I hate when people say this, as if there's any world in which I would want my AWS API gateway to do this, let alone accidentally. HTTP is littered with these footguns, differences between slashes and no slashes is a classic. A good piece of software would make it hard to do this by accident, and probably should default to having the same behaviour with or without trailing slash.

Yes yes, I know, folder/file naming convention dating from...

But it's current year now

sam_lowry_•13m ago
HTTP footguns? Meh! I routinely bypass domain blocks by appending a dot to the domain name, e.g. amazon.com.
rvz•16m ago
The thing that absolutely should not be vibe coded, especially in fintech.

Turning a $10 bug into a $12K issue and if this was at a big tech company it would be a $120K+ issue.

brian_herman•15m ago
You deserve the trip, nice find!
praptak•9m ago
Appending stuff to bypass blacklists is eternal.

My first job, decades ago. I couldn't update something on my laptop because client's gateway blocked `http://foo.com/update.exe`. Guess what, `http://foo.com/update.exe?` worked as a bypass.

anacrolix•9m ago
That's what you get for using Go mux

Daily Murder: a daily whodunit puzzle solved by logic on an elimination grid

https://dailymurder.com
1•KeepComputing•27s ago•0 comments

My Favorite Fable

https://sive.rs/horses
1•Michelangelo11•39s ago•0 comments

Skill to Income Mapping Engine

https://www.tooldocket.com/2026/05/skill-to-income-calculator.html
1•stoicstoic•40s ago•0 comments

Study: AI is helping to develop new gallium-based semiconductor

https://news.flinders.edu.au/blog/2026/05/26/ai-speeds-up-discovery-of-next-gen-computer-chips-an...
1•giuliomagnifico•1m ago•0 comments

Netherlands blocks U.S. takeover of DigiD operator Solvinity

https://nltimes.nl/2026/05/26/netherlands-blocks-us-takeover-digid-operator-solvinity-security-co...
1•nemoniac•3m ago•0 comments

IT Doesn't Matter [pdf]

https://www.classes.cs.uchicago.edu/archive/2014/fall/51210-1/required.reading/ITDoesntMatter.pdf
1•harlequinetcie•8m ago•0 comments

DBase is back, sort-of... Error: database not found

https://delphinightmares.substack.com/p/dbase-is-back-sort-of
1•deeaceofbase•11m ago•1 comments

Show HN: High-performance parallel save/load for large NumPy

https://github.com/NoteDance/parallel-saver
1•NoteDance•12m ago•0 comments

Steve Jobs MIT Sloan Distinguished Speaker Series (1992)

https://www.youtube.com/watch?v=Gk-9Fd2mEnI
1•downbad_•16m ago•0 comments

"Peak Civilization": The Fall of the Roman Empire (2009)

http://theoildrum.com/node/5528
1•downbad_•17m ago•0 comments

China vs. Taiwan: The Geography of an Unfinished War

https://jstribune.com/china-vs-taiwan-the-geography-of-an-unfinished-war/
1•bryanrasmussen•18m ago•0 comments

The AI bubble isn't like the internet bubble

https://pluralistic.net/2026/05/26/the-ai-will-continue/#until-morale-improves
3•doener•20m ago•1 comments

Sparse Autoencoders Reveal Cortical Brain-LLM Semantic Mapping

https://letsdatascience.com/news/sparse-autoencoders-reveal-cortical-brain-llm-semantic-mappi-bc5...
2•bryanrasmussen•21m ago•0 comments

BBC program on wave-powered boats [video]

https://www.youtube.com/watch?v=UWpxtfmpVD4
1•msuniverse2026•22m ago•0 comments

Microsoft and Uber Are Running into an AI Cost Problem

https://firethering.com/microsoft-uber-ai-coding-tools-more-expensive-than-human-workers/
4•steveharing1•24m ago•2 comments

StyloBot- Open Source self hosted behavioural bot protection

https://stylobot.net
1•scottgal•26m ago•0 comments

Benchmarking Vortex File Format vs. Parquet, CSV vs. DuckDB, Polars, Datafusion

https://dataengineeringcentral.substack.com/p/benchmarking-vortex-file-format-vs
1•eigenBasis•26m ago•0 comments

Raft Consensus with a Minority of Nodes

https://padhye.org/raft-minority/
1•moarbugs•27m ago•0 comments

Delta Brain Sync · Streamlit

https://delta-brain-sync-k99vym7mbyebesrfdl84sm.streamlit.app
1•TELEFOXX•27m ago•0 comments

Solar, wind and batteries push down electricity bills for homes and business

https://reneweconomy.com.au/solar-wind-and-batteries-push-down-electricity-bills-for-homes-and-bu...
2•doener•27m ago•0 comments

EU plans to fine Google high triple-digit million euro sum, Handelsblatt reports

https://www.reuters.com/world/europe/eu-plans-fine-google-high-triple-digit-million-euro-sum-hand...
2•LelouBil•28m ago•0 comments

PHP – simple way to send HTTP headers before a script ends

https://shkspr.mobi/blog/2026/05/php-simple-way-to-send-http-headers-before-a-script-ends/
1•blenderob•28m ago•0 comments

Terjangkau: Neighborhood Explorer

https://github.com/altilunium/terjangkau
1•altilunium•28m ago•0 comments

Prompter – Compare and benchmark Ollama models side-by-side in your terminal

https://github.com/whonixnetworks/prompter
1•whonixnetworks•30m ago•0 comments

Show HN: Self-managing codebase with long-horizon agents

https://github.com/WillTaylor22/self-managing-codebase
1•wrftaylor•32m ago•1 comments

"Long-Term Support" doesn't mean what you think

https://pointieststick.com/2026/05/23/long-term-support-doesnt-mean-what-you-think/
2•birdculture•33m ago•0 comments

Five foundations for building complex Ruby on Rails apps

https://paweldabrowski.com/farewell-to-rails-way/five-foundations-for-building-complex-rails-apps
1•pdabrowski6•35m ago•0 comments

Tools and skills for humans and agents to review via Magnifica Humanitas

https://encyclical.ai/
2•willf•36m ago•0 comments

NL govt blocks DigiD takeover by solvinity

https://nos.nl/artikel/2615885-staatssecretaris-verbiedt-overname-solvinity-bedrijf-achter-digid
5•hvb2•45m ago•1 comments

Show HN: Judicex – Open-source legal AI that abstains instead of hallucinating

https://github.com/JustVugg/judicex
3•vforno•48m ago•0 comments