Загрузка видео...

Не удалось загрузить видео

На главную

How did I test the IDOR vulnerability that leads to all user Data leakage? 1:Change the /me endpoint to /users. 2.Change the GET method to the POST method. 3.Add the Content-Type: application/json header. 4.Add this payload to the HTTP request body. {"ids":["1"]} #bugbountytips

41,448 просмотров • 3 лет назад •via X (Twitter)

Комментарии: 8

Фото профиля st0x_r0
st0x_r03 лет назад

Hey bro, how did you find out about this loophole?🤔🤔

Фото профиля Aydin Naserifard
Aydin Naserifard3 лет назад

the rest, you know. Just for point number 4, there was no ids parameter, which should have been seen in the response with the /users or /me endpoints. I tried the hit-and-trial method.

Фото профиля ashu (logic-cracker)
ashu (logic-cracker)1 год назад

reallly nice thank you bro really appreaciated .........

Фото профиля 0xm1racle
0xm1racle3 лет назад

Im curious how this vulnerability occured

Фото профиля Aydin Naserifard
Aydin Naserifard3 лет назад

the rest, you know. Just for point number 4, there was no ids parameter, which should have been seen in the response with the /users endpoint. I tried the hit-and-trial method.

Фото профиля Md. Amin Ullah Sheikh
Md. Amin Ullah Sheikh3 лет назад

Great bro

Фото профиля huntk1ng
huntk1ng3 лет назад

@SaveToNotion #tweets #idor

Фото профиля tjmald
tjmald3 лет назад

@SaveToNotion #Tweet #idor

Похожие видео