Of course both vulnerabilities from the serverside and clientside are indispensable perfect penetration test. Here s the end of story and generally speaking it was rather interesting experience xD Thanks this event inspired me write some articles about penetration Last but not least would like Bug Bounty tolerant Facebook Security Team that could fully down incident Timeline Provide vulnerability details Receive automatic response Submit Advisory Accellion Support from Thomas inspection progress Reginaldo receiving award USD Asking if there anything should pay special attention blog post be classify RCE SQL Injection forensics investigation you able hold your until process complete Hai will include March payments cycle [...]