Back to directory
WRITEUP #5452

My very first bug: a dreaded dupe and then an IDOR jackpot!

IDOR
by@JohnH4X00R(John H4X00R)
Bounty
5,000
Program
Yahoo! / Verizon Media
Published
Mar 28, 2019
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://medium.com/h4x00r/my-very-first-bug-a-dreaded-dupe-and-then-an-idor-jackpot-d01b69f6fbae
RELATED WRITEUPS
Zomatoooo! IDOR in Saved Payments
IDOR
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
A Creative Way To Get Someones YouTube Videos Deleted + A Copyright Strike Against Their YouTube Channel
IDORBroken Access Control
Bypassing ACLs – IDOR exploitation via HPP
IDORHTTP parameter pollution

Built with ❤️ by Shubham Rawat