My Bug Bounty Journey #8: How an Unintentional Mistake Led to a Floor Plan Leak
quality 2/10 · low quality
0 net
Tags
My Bug Bounty Journey #8: How an Unintentional Mistake Led to a Floor Plan Leak | by awchjimmy - Freedium
Milestone: 20GB Reached
We’ve reached 20GB of stored data — thank you for helping us grow!
Patreon
Ko-fi
Liberapay
Close
< Go to the original
My Bug Bounty Journey #8: How an Unintentional Mistake Led to a Floor Plan Leak
The Story
awchjimmy
Follow
~2 min read
·
April 9, 2026 (Updated: April 9, 2026)
·
Free: Yes
The Story
Hi, I'm Jimmy. I created this series to share my bug bounty experiences. This story is from one of my early findings.
Although this particular report was eventually closed as "out of scope," the whole process was still exciting and worth sharing.
Let's get started.
The Bug
One day, I came across a company's building floor plans hosted on a popular site, readthedocs.io. The exposed documentation included detailed interior layouts. Showing where industrial equipment was located and even how to operate some of the machines.
Why It Happened
Maybe it was meant to make things easier for vendors coming on-site for maintenance, or to help share knowledge between vendors and internal staff. Either way, these documents were unintentionally made public on readthedocs.io.
What I Learned
Every bug bounty hunter is told to use search engines like Google, Bing, or Yahoo for reconnaissance. Some also check GitHub. But many stop there.
The truth is, valuable data is scattered all across the internet. If a platform is popular among developers, it's probably worth searching. Think GitHub, GitLab, or even Docker Hub.
Don't limit yourself to just one or two search engines. Be curious and creative. That's what sets you apart from the average hunter.
Stay Tuned
That's it for today. More to come soon.
If you'd like to support me, feel free to buy me a coffee:
https://ko-fi.com/awchjimmy
#bug-bounty #web-development #cybersecurity
Reporting a Problem
Sometimes we have problems displaying some Medium posts.
If you have a problem that some images aren't loading - try using VPN. Probably you have problem with
access to Medium CDN (or fucking Cloudflare's bot detection algorithms are blocking you).