Back to directory
WRITEUP #5266

Tale of account takeover — Sensitive info Disclosure + Broken Access Control

IDORAccount takeover
by@sakyb7(Md Saqib)
Bounty
2,650
Program
-
Published
Jul 10, 2019
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://medium.com/@sakyb7/tale-of-account-takeover-sensitive-info-disclosure-broken-access-control-cea0a5e3a1fd
RELATED WRITEUPS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
Self-XSS to ATO via Site Features
XSSSelf-XSS
Zomatoooo! IDOR in Saved Payments
IDOR
CSRF Bypass Using Domain Confusion Leads To ATO
CSRFAccount takeover

Built with ❤️ by Shubham Rawat