IDOR in APPLE 🍎
POC ->
1. Created two separate user accounts Account A (attacker), Account B (victim) on
https://t.co/veSFHH5zMp[.]com/publicLocator/deleteApplication
https://t.co/veSFHH5zMp[.]com/publicLocator/submitJoinForm
2. Logged in as Account B, submited the application form and captured the application ID of Account B
3. Now Log in as Account A and intercepted a request to the affected endpoint
4. Replaced Account A’s application ID with Account B’s application ID.
5. Forwarded the modified request
6. Server accepted the request without authorization validation
7. Logged back into Account B
8. Account B’s data is modified or deleted without consent
Impact ->
Any authenticated user can modify or delete other users’ data
Credited to the respected owner
#bugbounty #bughunting #bounty #hacking #ethicalhacking #infosec #cybersecurity #bugbountytips #bugbounty #bugbountytip #bughunting #infosecurity #OWASP #ApplicationSecurity #Bugcrowd #Hackerone #day_20
day - 8 of ML
> revised linear reg .
> build a streamlit app to make package pridiction .
> optimized it with gradient descent .
> started mathematical formulation of batch gd .
#DataScientist#machinelearningquiz#ChatGPT#AI