today I crossed 23 years, one year ago I got arrested for illegal hacking and I was about going to jail but thanks god and I thank everyone from the bug bounty hunting community for changing my life from the worst to the better especially
@NahamSec@Jhaddix@Bugcrowd@Hacker0x01
@skulldentist @chanukaisdumb @Bug_X_hunter bro it's not guessing here for UUID you can retrieve from different ways such as (archive-dorks-github) and for uber program they do accept idor on UUID
@skulldentist @chanukaisdumb @Bug_X_hunter no i was able to see anyone data. that was the vulnerable endpoint: https://t.co/4Vibg6z8dL
so basically any new order happened in right momment with the right uuid you will be able to see the data of otehr customers ( driver - geolocation)
@Bug_X_hunter And the problem happened i did not realize there is time bounding and the triager while doing the assessment the information already deleted
@chanukaisdumb @Bug_X_hunter@skulldentist No they did not , and it's not full positive , the problem as i said about time bounding, after u order the 48 hours i can see driver info and the geolocation info after 48 hours those information automatically deleted by system
@stilla1ex unicode is much more effective but i think most of host providers patch it since you can register any domain with other keyboards schemes and it will exactly match the keywords