Mohamed reda ameen(@M0x0101) 's Twitter Profile Photo

Hello everyone,I discovered an IDOR vulnerability based on user IDs, but the IDs seem to be generated using a certain date pattern,it's 24-character hexadecimal string, Any ideas on how I can detect the user ID?

account_circle
HappyKira0x1(@HappyKira9) 's Twitter Profile Photo

Amazing Week๐Ÿ”ฅ
-->Tip1:
Always try all CSRF bypass protection token techniques.
-->Tip2:
Read Api documentation, test for IDOR in any endpoint.

bugcrowd

Amazing Week๐Ÿ”ฅ
-->Tip1:
Always try all CSRF bypass protection token techniques.
-->Tip2:
Read Api documentation, test for IDOR in any endpoint.

@Bugcrowd
#BugBounty
#bugbountytips
account_circle
Walid Hossain(@walidhossain010) 's Twitter Profile Photo

I earned $3900 for my submission on @bugcrowd bugcrowd.com/walidhossain

1xP1 - idor to takeover org
2xP3 - idor
2xP4 - idor,csrf

account_circle
Maldor๐Ÿ(@CommanderMaIdor) 's Twitter Profile Photo

Struggler Hates it Here Well AC Valhalla takes place around 850 and Vinland is after 1000 is chances are it's not canon, but kinda funny to think about tho lol

account_circle
loukoumpetit.eth(@loukoum_petit) 's Twitter Profile Photo

When you are testing requests in burp repeater, if you have a 403 error code, check whether it has been executed.
I just found an IDOR when the repeater gave me a 403 error code.๐Ÿ•บ

tips

account_circle
Axios(@axios) 's Twitter Profile Photo

As more companies seek out tracking data, climate-focused AI and robotics companies are attracting investors. Via Axios Pro.

account_circle
Martin Crowley(@AIToolReport) 's Twitter Profile Photo

AI wonโ€™t replace you. A person using AI will.

Join 45,000+ readers and get smart about AI in less than 3 minutes a day. ๐Ÿ‘‡

account_circle
RadheSec(@RadheSec) 's Twitter Profile Photo

Some of the major vulnerabilities and related POCโ€™s:

โžกSQLi
โžกXSS
โžกSSRF
โžกXXE
โžกPath Traversal
โžกOpen Redirection
โžกAccount Takeover
โžกRemote code execution
โžกIDOR
โžกCSRF

tips

Are Found Below๐Ÿงต(1/n)๐Ÿ‘‡

account_circle
็‘ช็‘™(ใ‚ใฎใ†)(@sinkai_idor) 's Twitter Profile Photo

โค๏ธŽ ใ‚ใ‚ โค๏ธŽ ไปŠใ€ไผšๅ ดใ‹ใ‚‰้›ขใ‚Œใฆใ„ใ‚‹ใฎใงใ€้–‹ๅ ดๅพŒor็ต‚ไบ†ๅพŒใซไบคๆ›ใงใ‚‚ๅฏ่ƒฝใงใ—ใ‚‡ใ†ใ‹๏ผŸ

account_circle
ใ‹ใˆใ‚‹(@m_idor) 's Twitter Profile Photo

่ก€ๅœงๆธฌๅฎš
ไธ€ๆ—ฅไธ€ๅ›žๆธฌใ‚‹ใ“ใจใ‹ใ‚‰ๅง‹ใ‚ใ‚‹๐Ÿ˜”

่ก€ๅœงๆธฌๅฎš
ไธ€ๆ—ฅไธ€ๅ›žๆธฌใ‚‹ใ“ใจใ‹ใ‚‰ๅง‹ใ‚ใ‚‹๐Ÿ˜”
account_circle
ใ‹ใˆใ‚‹(@m_idor) 's Twitter Profile Photo

ใ•ใ‚„้ฆ™ใฎๆ–ฐๅฑฑใ•ใ‚“
ไฟณๅ„ชๆฅญใ‚„ใ‚‰ใชใ„ใ‹ใชใ

account_circle