Back to directory
WRITEUP #6270

Hey UserID x, what’s your secret token? Broken API enables me to leak/modify any users personal information

IDORAccount takeover
by@zseano(Zseano)
Program
-
Published
Jul 13, 2017
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://zseano.medium.com/fun-with-mobile-apps-broken-api-leads-to-leak-of-millions-of-personal-information-e7eb0b9dcce7
RELATED WRITEUPS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
Self-XSS to ATO via Site Features
XSSSelf-XSS
Zomatoooo! IDOR in Saved Payments
IDOR
CSRF Bypass Using Domain Confusion Leads To ATO
CSRFAccount takeover

Built with ❤️ by Shubham Rawat