Back to directory
WRITEUP #5730

IDOR in JWT and the shortest token you will ever see {}.{“uid”: “1234567890”}

IDOR
by@plenumlab(Plenum)
Bounty
1,500
Program
-
Published
Oct 30, 2018
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://medium.com/@plenumlab/idor-in-jwt-and-the-shortest-token-you-will-ever-see-uid-1234567890-4e02377ea03a
RELATED WRITEUPS
Zomatoooo! IDOR in Saved Payments
IDOR
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
A Creative Way To Get Someones YouTube Videos Deleted + A Copyright Strike Against Their YouTube Channel
IDORBroken Access Control
Bypassing ACLs – IDOR exploitation via HPP
IDORHTTP parameter pollution

Built with ❤️ by Shubham Rawat