๐• Bug Bounty Writeups ๐•
๐• Bug Bounty Writeups ๐• @bountywriteups ยท
Finding an IDOR in User Profile API: A $15,000 Journey to Critical xalgord.medium.com/finding-an-idoโ€ฆ #bugbounty #bugbountytips #bugbountytip
๐Ÿ›๐Ÿ’ฐ๐Ÿ”“๐ŸŽฏ Finding an IDOR in User Profile API: A $15,000 Journey to Critical

How I discovered a critical Insecure Direct Object Reference vulnerability that allowed unauthorized access to any user profile โ€” and howโ€ฆ

From xalgord.medium.com
2
316
Mo7amed ๐Ÿฅท
Mo7amed ๐Ÿฅท @0xMo7areb ยท
ู†ุตูŠุญุฉ ู…ู† ุงู„ุจุฌ ู‡ุงู†ุชุฑุฒ ุจุชุถุจุท ูŠูˆู…ูƒ ู…ุง ุจูŠู† ู…ุฐุงูƒุฑุฉ ุซุบุฑุฉ ูˆู‚ุฑุงุกุฉ writeups ูˆุงู„ู‡ุงู†ุชูŠุฌ ุงุฒุงูŠ ุŸ ูˆู‡ู„ ููŠู‡ ู†ุงุณ ู…ุซู„ุง ู…ุฎุตุตุฉ ุฃู†ู‡ุง ุชุฐุงูƒุฑ ูŠูˆู… ูˆุชู‡ุงู†ุช ูŠูˆู… ูˆูƒุฏู‡ ูˆู„ุง ุงูŠู‡ ุจุฑุฏูˆ ุŸ #bugbountytips
71
TheHatedOne
TheHatedOne @3ugman ยท
How these hunters are finding critical vulnerability on AT&T program, whenever I submit an issue, within 1 day it will be closed as not applicable because the domain was out of scope ๐Ÿ˜‚๐Ÿ˜ญ. Huge respect to the hunters who finding correct in-scope domains of AT&T ๏ฟฝ๏ฟฝ. #bugbountytips
72