<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Hakkabaka</title><description>A small blog in big cyber space.</description><link>https://hakkabaka.dev/</link><item><title>Finding an IDOR by Learning the App’s Role Model</title><link>https://hakkabaka.dev/posts/2026/finding-idor-pm-case-study/</link><guid isPermaLink="true">https://hakkabaka.dev/posts/2026/finding-idor-pm-case-study/</guid><description>How understanding roles, visibility states, and configuration gates led to discovering an IDOR in a project management system</description><pubDate>Tue, 17 Mar 2026 05:17:19 GMT</pubDate></item></channel></rss>