Video wird geladen...
Video konnte nicht geladen werden
How did I test the IDOR vulnerability that leads to all user Data leakage? 1:Change the /me endpoint to /users. 2.Change the GET method to the POST method. 3.Add the Content-Type: application/json header. 4.Add this payload to the HTTP request body. {"ids":["1"]} #bugbountytips
41,434 Aufrufe • vor 3 Jahren •via X (Twitter)
8 Kommentare

st0x_r0vor 3 Jahren
Hey bro, how did you find out about this loophole?🤔🤔

Aydin Naserifardvor 3 Jahren
the rest, you know. Just for point number 4, there was no ids parameter, which should have been seen in the response with the /users or /me endpoints. I tried the hit-and-trial method.

ashu (logic-cracker)vor 1 Jahr
reallly nice thank you bro really appreaciated .........

0xm1raclevor 3 Jahren
Im curious how this vulnerability occured

Aydin Naserifardvor 3 Jahren
the rest, you know. Just for point number 4, there was no ids parameter, which should have been seen in the response with the /users endpoint. I tried the hit-and-trial method.

Md. Amin Ullah Sheikhvor 3 Jahren
Great bro

huntk1ngvor 3 Jahren
@SaveToNotion #tweets #idor

tjmaldvor 3 Jahren
@SaveToNotion #Tweet #idor



