Back to directory
WRITEUP #5612

How I Was Able To Takeover All User Account And Admin Panel

IDORAccount takeover
by@d1pakdas(Dipak kumar Das)
Bounty
1,500
Program
-
Published
Dec 28, 2018
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://addictivehackers.blogspot.com/2018/12/how-i-was-able-to-takeover-all-user.html
RELATED WRITEUPS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
Self-XSS to ATO via Site Features
XSSSelf-XSS
Zomatoooo! IDOR in Saved Payments
IDOR
CSRF Bypass Using Domain Confusion Leads To ATO
CSRFAccount takeover

Built with ❤️ by Shubham Rawat