I got permission from a founder to attack his real production app.
So I did.
No sandbox. No fake vulnerable app. No CTF.
The same live product real users are touching.
100% authorized.
And I did it using an obliterated model.
Iโll tell you which one tonight.
Tonight Iโm posting what happened when I stopped using it like a customer and started trying to break it. ๐