正在加载视频...

视频加载失败

How did I test the IDOR vulnerability that leads to all user Data leakage? 1:Change the /me endpoint to /users. 2.Change the GET method to the POST method. 3.Add the Content-Type: application/json header. 4.Add this payload to the HTTP request body. {"ids":["1"]} #bugbountytips

41,448 次观看 • 3 年前 •via X (Twitter)

8 条评论

st0x_r0 的头像
st0x_r03 年前

Hey bro, how did you find out about this loophole?🤔🤔

Aydin Naserifard 的头像
Aydin Naserifard3 年前

the rest, you know. Just for point number 4, there was no ids parameter, which should have been seen in the response with the /users or /me endpoints. I tried the hit-and-trial method.

ashu (logic-cracker) 的头像
ashu (logic-cracker)1 年前

reallly nice thank you bro really appreaciated .........

0xm1racle 的头像
0xm1racle3 年前

Im curious how this vulnerability occured

Aydin Naserifard 的头像
Aydin Naserifard3 年前

the rest, you know. Just for point number 4, there was no ids parameter, which should have been seen in the response with the /users endpoint. I tried the hit-and-trial method.

Md. Amin Ullah Sheikh 的头像
Md. Amin Ullah Sheikh3 年前

Great bro

huntk1ng 的头像
huntk1ng3 年前

@SaveToNotion #tweets #idor

tjmald 的头像
tjmald3 年前

@SaveToNotion #Tweet #idor

相关视频