Time for a critical vulnerability discovery story. 📖
Gather around folks. Based on a true story - some details changed for anonymity.
A pentester (let's call him Jerry) was testing a critical application, it was controlling a gigantic water processing plant for a major global city. He sat down on the first day of testing and was greeted with a custom SSO sign-in page. He fired up Burp Suite, enabled interception, and walked through the login flow.
He got most of the way through the SSO flow without seeing anything overly suspicious. The login looks as though it has been successful, but he notices one last POST request pop up in proxy intercept before he's redirected to /dashboard. It's being sent to /login and it just has a JSON body {"user_id":"pentest@example[.].com"}. No password, no auth token, just an email.
He switches "pentest@" to "admin@" and is greeted with full admin privileges. All before morning tea.
After some further testing, he realised that you didn't even need the SSO flow, anyone could just send a POST request with the email of the user they wish to authenticate as, and the response would contain be a session token for that user. 👌
The moral of the story: sometimes, the most critical vulnerabilities are so obvious that most people don't even bother to check for them. 80% of pentesting is just validating assumptions!
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: https://t.co/jD6EaGtsn3
🚨I HAVE LEAKED EVERY SINGLE PASSWORD EVER (4 to 32 chars long)!
That is 347 novemdecillion passwords, the largest password leak ever!
ALL of your passwords are in here, GUARANTEED!
This is a client-side app, so what you search for is all local, never sent anywhere.
📢 𝗡𝗲𝘄 𝗘𝘅𝗮𝗺 𝗟𝗮𝘂𝗻𝗰𝗵: 𝗖𝗲𝗿𝘁𝗶𝗳𝗶𝗲𝗱 𝗔𝗣𝗜 𝗣𝗲𝗻𝘁𝗲𝘀𝘁𝗲𝗿 (𝗖-𝗔𝗣𝗜𝗣𝗲𝗻) 📢
𝙇𝙞𝙠𝙚, 𝙍𝙚𝙨𝙝𝙖𝙧𝙚, 𝙖𝙣𝙙 𝙁𝙤𝙡𝙡𝙤𝙬 𝙛𝙤𝙧 𝙖 𝘾𝙝𝙖𝙣𝙘𝙚 𝙩𝙤 𝙒𝙞𝙣 𝘽𝙞𝙜!
🎉 3 lucky winners will receive the C-APIPen exam for FREE!
🎟️ 𝗦𝗽𝗲𝗰𝗶𝗮𝗹 𝗢𝗳𝗳𝗲𝗿: Get a massive 80% Discount on C-APIPen, one of our exclusive exams!
𝗨𝘀𝗲 𝗣𝗿𝗼𝗺𝗼 𝗖𝗼𝗱𝗲: API-80-OFF
𝘗𝘶𝘳𝘤𝘩𝘢𝘴𝘦 𝘯𝘰𝘸 𝘵𝘰 𝘴𝘦𝘤𝘶𝘳𝘦 𝘺𝘰𝘶𝘳 𝘥𝘪𝘴𝘤𝘰𝘶𝘯𝘵 𝘢𝘯𝘥 𝘵𝘢𝘬𝘦 𝘵𝘩𝘦 𝘦𝘹𝘢𝘮 𝘢𝘵 𝘺𝘰𝘶𝘳 𝘤𝘰𝘯𝘷𝘦𝘯𝘪𝘦𝘯𝘤𝘦.
🛡️ 𝗖-𝗔𝗣𝗜𝗣𝗲𝗻 𝗢𝘃𝗲𝗿𝘃𝗶𝗲𝘄: C-APIPen is an intense 4 hours long practical exam. This exam rigorously tests your in-depth knowledge of API security and practical API pentesting skills.
❓𝗪𝗵𝗼 𝗰𝗮𝗻 𝘁𝗮𝗸𝗲 𝘁𝗵𝗶𝘀 𝗲𝘅𝗮𝗺?
C-APIPen is intended to be taken by pentesters, application security architects, SOC analysts, red and blue team members, and any security enthusiasts who want to evaluate and advance their knowledge.
*𝗡𝗼𝘁𝗲: 𝘛𝘩𝘦 𝘦𝘹𝘢𝘮 𝘥𝘦𝘵𝘢𝘪𝘭𝘴 𝘸𝘪𝘭𝘭 𝘣𝘦 𝘴𝘦𝘯𝘵 𝘵𝘰 𝘺𝘰𝘶 𝘰𝘯/𝘣𝘦𝘧𝘰𝘳𝘦 15 𝙅𝙖𝙣𝙪𝙖𝙧𝙮 2025.
🔗 𝗚𝗲𝘁 𝗦𝘁𝗮𝗿𝘁𝗲𝗱 𝗡𝗼𝘄: https://t.co/scMG8UvUrj
#CyberSecurity #APISecurity #PenTesting #EthicalHacking #InfoSec #API #SecurityTesting #SecOps #CyberSkills #LearnCybersecurity #APIPenTesting
@Burp_Suite Bambda Script, leveraging ChatGPT for accurate API endpoint prediction. Find the code on GitHub: https://t.co/mvmzQ713NV
Supported by both Burp Suite Community and Pro editions
#Bambdas#bugbounty
الحمدالله
بفضل الله وتوفقيه حقق فريقنا (OSINTMe) المركز الرابع في #تحدي_الأمن_السيبراني23 المقدم من @Thakaa_Center و @site_saudi
فخورين بهذا الانجاز
وكل الشكر و التقدير لفريقنا الرائع على جهودهم
@z5jt4
@ShrAin9
اوجه جزيل الشكر لقائد الفريق و داعمنا الاول
@talal_raji