Back to directory
WRITEUP #2459

A Developer’s Nightmare: Story of a simple IDOR and some poor fixes worth $1125

IDOR
by@marcos_iaf(Marcos IAF)
Bounty
1,125
Program
-
Published
Jul 24, 2022
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://medium.com/@720922/a-developers-nightmare-story-of-a-simple-idor-and-some-poor-fixes-worth-1125-5ead70b0a1de
RELATED WRITEUPS
Zomatoooo! IDOR in Saved Payments
IDOR
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
A Creative Way To Get Someones YouTube Videos Deleted + A Copyright Strike Against Their YouTube Channel
IDORBroken Access Control
Bypassing ACLs – IDOR exploitation via HPP
IDORHTTP parameter pollution

Built with ❤️ by Shubham Rawat