Favour Idowu | cracker ๐ŸŽญ

1.8K posts

Favour Idowu | cracker ๐ŸŽญ banner
Favour Idowu | cracker ๐ŸŽญ

Favour Idowu | cracker ๐ŸŽญ

@favour_eng

A Creative Software Engineer ๐Ÿ˜ตโ€๐Ÿ’ซ| Penetration tester | Dreaming Big - Taking actions | Building https://t.co/Ryxqohniau

@Space ๊ฐ€์ž…์ผ Haziran 2023
1.1K ํŒ”๋กœ์ž‰312 ํŒ”๋กœ์›Œ
๊ณ ์ •๋œ ํŠธ์œ—
Favour Idowu | cracker ๐ŸŽญ
Favour Idowu | cracker ๐ŸŽญ@favour_engยท
I build Scalable web based Applications for founders and businesses What do you do?
Favour Idowu | cracker ๐ŸŽญ tweet media
English
0
0
3
312
Kath Korevec
Kath Korevec@simpsokaยท
Gm. Itโ€™s my birthday today. Taking the day to enjoy this. Hope yโ€™all have a good day!!
Kath Korevec tweet media
English
83
0
357
14.8K
Framer
Framer@framerยท
Who needs some followers? Drop your @framer community profile below so everyone knows who you are!
English
403
12
250
18.1K
Favour Idowu | cracker ๐ŸŽญ ๋ฆฌํŠธ์œ—ํ•จ
Favour Idowu | cracker ๐ŸŽญ
Favour Idowu | cracker ๐ŸŽญ@favour_engยท
I'm tired of getting 3 likes man. I need brothers and sisters in tech, AI, startups, marketing, distribution, vibecoding to come to my rescue. Let's connect
English
1
1
1
43
Favour Idowu | cracker ๐ŸŽญ ๋ฆฌํŠธ์œ—ํ•จ
Favour Idowu | cracker ๐ŸŽญ
Bro, Confidence is almost everything, You might be smart but the person with confidence will win you alwaysโ€ฆ
English
0
1
1
20
Favour Idowu | cracker ๐ŸŽญ ๋ฆฌํŠธ์œ—ํ•จ
Favour Idowu | cracker ๐ŸŽญ
If you are certain that, a day would come where millions would use your Solutions. Quote this with what you are building. #connect.
English
0
1
2
30
Favour Idowu | cracker ๐ŸŽญ
Now AI can build and ship features in few seconds, Itโ€™s really hard to keep things simple,
English
0
1
1
9
Katie Paxton-Fear
Katie Paxton-Fear@InsiderPhDยท
Youโ€™ll never guess what my favourite display technology is
Katie Paxton-Fear tweet media
English
13
0
35
3K
Marques Brownlee
Marques Brownlee@MKBHDยท
NEW VIDEO - Adding a touchscreen to the Macbook Pro to feel what it would be like when the rumored Ultra finally does come out: youtu.be/WOzcFkld6_g
YouTube video
YouTube
Marques Brownlee tweet media
English
52
73
2.6K
194.9K
Elon Musk
Elon Musk@elonmuskยท
It is humbling to consider that if we harness just 1 millionth of the Sunโ€™s power for AI, that will be much more than a million times the intelligence of all of humanity
English
14.9K
17.4K
203.9K
27.5M
Chisom Nwokwu๐ŸŒŸ
Chisom Nwokwu๐ŸŒŸ@tech_queenยท
SpaceX is acquiring Cursor for $60B๐Ÿคฏ
English
3
4
38
2.7K
Favour Idowu | cracker ๐ŸŽญ
Spent way longer than Iโ€™d like to admit debugging a CORS error on Pyramid Schoolโ€™s backend. Turns out it wasnโ€™t Flask at all, it was how Vercel was proxying requests to Render. Fixed now. Onward ๐Ÿš€
English
0
0
0
10
Favour Idowu | cracker ๐ŸŽญ ๋ฆฌํŠธ์œ—ํ•จ
Abdulkadir | Cybersecurity
Abdulkadir | Cybersecurity@cyber_razzยท
Every developer has written something like this at least once. Here is why it should never reach production. 1. No authentication or token verification This is the most critical one. Anyone who knows or guesses a valid email address can reset that userโ€™s password to anything they want. There is no reset token, no email verification step, no proof that the person making the request actually owns the account. You just send an email and a new password in a POST request and you own the account. That is not a password reset flow. That is an account takeover endpoint. 2. Password stored in plaintext The newPassword value goes directly into db.updatePassword with zero processing. No hashing. No salting. The password lands in the database exactly as the user typed it. If that database is ever breached, every single userโ€™s password is immediately readable in plain text. 3. No input validation There is no check on what newPassword actually contains. Empty string, a single character, null, a 10,000 character payload. All of it goes straight to the database. No length requirements, no complexity checks, nothing. 4. No rate limiting This endpoint accepts unlimited requests with no throttling or lockout mechanism. Combine this with vulnerability one and you have an endpoint that can be automated to take over accounts at scale. 5. User enumeration The endpoint only responds when a user exists. Silence on a non-existent email tells an attacker exactly which addresses are registered accounts. That information has real value in targeted attacks. Five vulnerabilities. Twelve lines of code. This is what happens when security is an afterthought.
Exploit-Forge@ExploitforgeLTD

How many vulnerabilities can you spot in this code?

English
2
5
22
41.8K