Loading video...

Video Failed to Load

Go Home

How did I test the IDOR vulnerability that leads to all user Data leakage? 1:Change the /me endpoint to /users. 2.Change the GET method to the POST method. 3.Add the Content-Type: application/json header. 4.Add this payload to the HTTP request body. {"ids":["1"]} #bugbountytips

41,448 views • 3 years ago •via X (Twitter)

8 Comments

st0x_r0's profile picture
st0x_r03 years ago

Hey bro, how did you find out about this loophole?🤔🤔

Aydin Naserifard's profile picture
Aydin Naserifard3 years ago

the rest, you know. Just for point number 4, there was no ids parameter, which should have been seen in the response with the /users or /me endpoints. I tried the hit-and-trial method.

ashu (logic-cracker)'s profile picture
ashu (logic-cracker)1 year ago

reallly nice thank you bro really appreaciated .........

0xm1racle's profile picture
0xm1racle3 years ago

Im curious how this vulnerability occured

Aydin Naserifard's profile picture
Aydin Naserifard3 years ago

the rest, you know. Just for point number 4, there was no ids parameter, which should have been seen in the response with the /users endpoint. I tried the hit-and-trial method.

Md. Amin Ullah Sheikh's profile picture
Md. Amin Ullah Sheikh3 years ago

Great bro

huntk1ng's profile picture
huntk1ng3 years ago

@SaveToNotion #tweets #idor

tjmald's profile picture
tjmald3 years ago

@SaveToNotion #Tweet #idor

Related Videos