Back to directory
WRITEUP #3669

This is how I was able to see Private, Archived Posts/Stories of users on Instagram without following them

IDORGraphQL
by@mayurfartade(Mayur Fartade)
Bounty
30,000
Program
-
Published
Jun 15, 2021
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://fartademayur.medium.com/this-is-how-i-was-able-to-see-private-archived-posts-stories-of-users-on-instagram-without-de70ca39165c
RELATED WRITEUPS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
Zomatoooo! IDOR in Saved Payments
IDOR
Authorization bypass due to cache misconfiguration
APIAuthorization bypass
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
A Creative Way To Get Someones YouTube Videos Deleted + A Copyright Strike Against Their YouTube Channel
IDORBroken Access Control

Built with ❤️ by Shubham Rawat