Back to directory
WRITEUP #5766

Get as image function pulls any Insights/NRQL data from any New Relic account (IDOR)

IDOR
by@jon_bottarini(Jon Bottarini)
Bounty
2,500
Program
New Relic
Published
Oct 9, 2018
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://jonbottarini.com/2018/10/09/get-as-image-function-pulls-any-insights-nrql-data-from-any-new-relic-account-idor/
RELATED WRITEUPS
Zomatoooo! IDOR in Saved Payments
IDOR
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
A Creative Way To Get Someones YouTube Videos Deleted + A Copyright Strike Against Their YouTube Channel
IDORBroken Access Control
Bypassing ACLs – IDOR exploitation via HPP
IDORHTTP parameter pollution

Built with ❤️ by Shubham Rawat