Back to directory
WRITEUP #2560

Access control worth $2000 (everyone missed this IDOR+Access control between two admins.)

IDORBroken Access Control
by@dhakal__bibek(dhakal_bibek)
Bounty
2,000
Program
-
Published
Jun 28, 2022
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://medium.com/pentesternepal/access-control-worth-2000-everyone-missed-this-idor-access-control-between-two-admins-9745eaf15d21
RELATED WRITEUPS
A Creative Way To Get Someones YouTube Videos Deleted + A Copyright Strike Against Their YouTube Channel
IDORBroken Access Control
Zomatoooo! IDOR in Saved Payments
IDOR
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
Vestaboard: Exploring Broken Access Controls and Privilege Escalation
Privilege EscalationBroken Access Control

Built with ❤️ by Shubham Rawat