This is how I was able to leak the cover pages of secret documents that were supposed to be private๐ฅ.
Check out my write-up below. I'd love to hear your thoughts and feedback.
#hackerone#Cybersecurity#ethicalhacking#cyberattacks#bugbounty
https://t.co/2sWJKfenwT
In this blog, I will discuss how a security vulnerability I discovered a year ago in Facebook/Meta could be used to affect the US election and how a simple IDOR vulnerability could have a major impact.
I hope you enjoy it :)
#USElection2024#bugbounty
https://t.co/mAc2F4LrjS
Found an endpoint:
โฆ/redacted?redirectionParam=/Path
1. Supplied any url: (Open redirect โ )
2.Supplied javascript:alert(1) ( XSS โ )
3.Created payload to steal the victimโs cookies and redirect them to our own website: ( ATO โ )
#BugBounty#bugbountytips#hackerone