Have you ever thought about exploiting an IDOR without any ID!? Returns sensitive data without any specific ID!?
https://t.co/vY23Xq83Xr
#bugbountytips#bugbountytip#infosecurity
5. The following Rack code takes the request protocol from the X-Forwarded-Scheme header, sending the http value for this header will returns 301 response... If this response is stored by the CDN, it will become a loop and DOS attack
#bugbountytip
@tabaahi_ Thank you β₯οΈ if admin doesn't invited you into circle you can not access comments. But if you join to the circle and then admin removes you, you have unauthorized access to comments. And the circle id wasn't uuid and attacker able to find the id of circle by exploring.
Some endpoints are hidden and to reach these endpoints should spend a good time on assets as a normal user! in this write-up, I will show you a sample of these scenarios!!
#bugbountytips#bugbountytip#infosecurity
https://t.co/f0FugmYJlI
I just published an attack vector which allow attacker to use logic of reset password function to locking victim's account. Hope you enjoyed β€οΈ
#bugbountytips#bugbountytip#bugbounty
https://t.co/dtZ1F5lQwm
@RelentlessT7 But why always change my report from P1 to P3?π e.g i reported a IDOR with read/edit/delete impact and triaged on p3 or one time i can sent custom sms from company number to anyone and triaged on p3 and company paid p3 reward. It's happening most of the time. LOL
I submitted a valid p1 bug on the @BugcrowdSupport but they reviewed my report after 5 days when the report not reproduce and subdomain was down.!!!
I gave them all data and all things to prove my report.
but they closed my report as N/A!
Please someone help me in this section
3. While developing an application, It's may the developer define some series of default UUIDs. If the programmer forgets to remove them before launching, may reveal sensitive information. Usually, these UUIDs are defined with values ββof 0 or 1 and
#bugbountytip
3. While developing an application, It's may the developer define some series of default UUIDs. If the programmer forgets to remove them before launching, may reveal sensitive information. Usually, these UUIDs are defined with values ββof 0 or 1 and
#bugbountytip
2. For OTP bypass while sending the OTP code to the victim, the attacker sets their phone number in the "country_isd" parameter and the victim's phone in the "phone_number" parameter. If the website is vulnerable, the victim's OTP code will sent to the attackers
#bugbountytips
2. For OTP bypass while sending the OTP code to the victim, the attacker sets their phone number in the "country_isd" parameter and the victim's phone in the "phone_number" parameter. If the website is vulnerable, the victim's OTP code will sent to the attackers
#bugbountytips
1. If you find a parameter in the GET request that was vulnerable to IDOR, but the value was UUID or unguessable, just look for leaked data in https://t.co/H2JJOwyWCx
#bugbountytip
1. If you find a parameter in the GET request that was vulnerable to IDOR, but the value was UUID or unguessable, just look for leaked data in https://t.co/H2JJOwyWCx
#bugbountytip