Black

63 posts

Black banner
Black

Black

@Bl4ckSec

Iraq Katılım Ocak 2024
123 Takip Edilen347 Takipçiler
Black
Black@Bl4ckSec·
@mbkartikreddy Read write-ups on Medium about Account Takeover
English
1
0
1
178
Karthik Reddy
Karthik Reddy@mbkartikreddy·
@Bl4ckSec congrats 🎉 can you share any resources so that i can learn too
English
1
0
2
406
Black
Black@Bl4ckSec·
🔴 IDOR Vulnerability Discovered an IDOR vulnerability in the Forgot Password feature. The issue is that the password reset token is not properly bound to the account email. An attacker with a valid reset token could change the password of another user’s account due to improper token validation. Example request structure: { "email": "victim@example.com", "newPassword": "NewPassword123!", "token": "VALID_RESET_TOKEN" } #bugbountytip #hackerone #infosec #BugBounty #Hacking
Black tweet media
English
3
8
239
7.9K
Black
Black@Bl4ckSec·
@Troll_13 Severity downgraded due to OTP
English
1
0
8
700
W31rd0
W31rd0@Troll_13·
@Bl4ckSec shouldn't this be Critical? or i am missing something
English
1
0
5
845
Black
Black@Bl4ckSec·
1. Bypassing invitation code restrictions: The code is intended for single-use and should expire immediately after the first user joins. 2. Lack of email-to-code binding: The invitation code is not linked to a specific email address, allowing it to be used by any unauthorized email.
English
0
0
2
48
Black
Black@Bl4ckSec·
I discovered a Race Condition vulnerability that allowed a single invitation code to be used across multiple accounts by accepting the invite from two accounts at the same time. In addition, there was insufficient validation of the account’s email address, which made it easier to exploit the issue and bypass the intended invite-only logic🔓. #BugBounty #bugbountytip #Hacking #InfoSec #CyberSecurity
Black tweet media
English
4
5
143
5.9K
Ozzy
Ozzy@Oluwakomiyo_·
@Bl4ckSec You mean you could use thesame invitation code for multiple accounts?
English
1
0
0
273
Megatron
Megatron@0xm394tr0n·
لو مشوفتش حاجه حلوه النهارده تعالي اوريك البج دي FULL ACCOUNT WILL DIE 😉 بس ف VDP Program🦧 تم رجوع ميجاترون وستارسكريم للهنت يابشر☝🏻 خد اقرا ومتع عنيك😉❤️‍🔥 متجربش دا ف البيت لاحسن ال لاب يفرقع ف وشك😂❤️‍🔥 لينك الرايتب: @omaroymdm/full-account-will-die-ce9958bccb8b" target="_blank" rel="nofollow noopener">medium.com/@omaroymdm/ful… #megatron #starscream #bugcrowd
Megatron tweet media
العربية
4
3
71
3.1K
Black
Black@Bl4ckSec·
@ide9x بطل 😍👏
العربية
0
0
3
236
a7madn1
a7madn1@a7mad__n1·
new bounty $$$🔥 Bug-type: Auth Bypass🫡 if you are interested to see real PoC, write ups,my google reports, self hosted programs, live bug hunting,and everything in Bug bounty, you can join my private channel,read details here t.me/a7madn1/141 #BugBounty #cybersecurity
a7madn1 tweet media
English
1
0
65
2.9K
Karan Jagtiani
Karan Jagtiani@karanjagtiani04·
@Bl4ckSec Is there a way to automate this testing for similar vulnerabilities?
English
1
0
0
164
Black
Black@Bl4ckSec·
🔴 IDOR Vulnerability Missing validation of user's relationship with org_id. The system relies only on memoryId without verifying organization ownership. { "org_id": "152ace33-d28f-4c21-bb8a-0130fe64bb24", "memoryId": "9f3c2a41-7b8e-4d6a-a2f1-3e6c8d9b1a42" } Modify or delete other organizations' data by simply changing the memoryId. #BugBounty #bugbountytips #Hacking #infosec
Black tweet media
English
12
17
329
12K
Black
Black@Bl4ckSec·
@zbsogood It depends on the program's policy.
English
0
0
1
199
zbcrypt
zbcrypt@zbcrypt·
@Bl4ckSec i submitted few of these uuid idors but only got informative they argued there is no way for an attacker to obtain the id
English
1
0
1
310
Black
Black@Bl4ckSec·
@ElzgroW You can find endpoints that leak the UUID
English
0
0
1
172
Black
Black@Bl4ckSec·
@nhyy_SA It depends on the program's policy.
English
0
0
1
131
Black
Black@Bl4ckSec·
@Joyerz5 It only depends on memoryId.
English
0
0
1
380
🔍mrro0o0tt
🔍mrro0o0tt@Joyerz5·
@Bl4ckSec "Modify or delete other organizations' data by simply changing the memoryId." Need to change both org_id & memoryId, RIGHT?
English
1
0
5
506
Black
Black@Bl4ckSec·
@grandfathersaha I created a memory in a different account and replaced the ID
English
0
0
2
426
bugoverflow
bugoverflow@bugoverfl0w·
@Bl4ckSec great, but why it is critical while UUID? and required PR Low or High?
English
1
0
6
1.2K
Black
Black@Bl4ckSec·
@s7a6k I'm merely proving a validation failure.
English
0
0
0
557
S7a6k
S7a6k@s7a6k·
@Bl4ckSec How you bro decrypting this id
English
1
0
1
625