Back to directory
WRITEUP #2868

Broken session control leads to access private videos using the shared link even after revoking the access for specific time!! — #GoogleVRP

OtherBroken Access Control
byNaveenroy
Program
Google
Published
Mar 20, 2022
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://naveenroy008.medium.com/broken-session-control-leads-to-access-private-videos-using-the-shared-link-even-after-revoking-the-84e31ac16fe4
RELATED WRITEUPS
Leaking All Users Google Drive Files
OtherBroken Access Control
Hacking Moodle Apps Via External Functions
OtherBroken Access Control
Data Theft in Salesforce: Manipulating Public Links
OtherSOQL injection
When Certificates Fail: A Story of Bypassed MFA in Remote Access
Other2FA / MFA bypass
SSTI in Bug Bounty Program: The Time I Played with Handlebars and Broke Stuff
OtherSSTI

Built with ❤️ by Shubham Rawat