Post

Roland Oodo | Full-Stack Engineer
1/ got a dm. "can you test our platform?" sure. that's my hobby. it was a govt voting platform. link dropped. frontend was gorgeous, whoever built it deserves a raise. then the engineer in me woke up.
Roland Oodo | Full-Stack Engineer tweet media
English
1
0
0
25
Roland Oodo | Full-Stack Engineer
2/ first thing i tried, vote without logging in. worked. no candidate shown to me even. just voted for whoever's name sounded sweet. don't ask.
English
1
0
0
2
Roland Oodo | Full-Stack Engineer
3/ asked myself, no login, so how do they know i already voted? tried again, got blocked. cookies. cleared them. reloaded. voted again. second round secured. i laughed for this one.
English
1
0
0
2
Roland Oodo | Full-Stack Engineer
4/ opened dev tools. fired a request. watched the response. PHP. not bad, i said. then i saw it, the response was leaking candidate IDs it had no business sending back. that's the door right there.
English
1
0
0
2
Roland Oodo | Full-Stack Engineer
5/ now i have every ID on the ballot. not clicking a UI 100 times clearing cookies like a mumu. spun up python. automated the whole flow. fired it.
English
1
0
0
4
Roland Oodo | Full-Stack Engineer
6/ 100 votes went through while i sat there nodding. didn't need to go further. sent the full report. what was solid, what was broken, what to fix.
English
1
0
0
9
Roland Oodo | Full-Stack Engineer
7/ moral: your frontend can wear armor, jet fighters, whatever attacker doesn't care how pretty your UI is. give them a terminal and your endpoints, and your "secure" system is wide open rate limit your backend. validate what you send back. build like someone's already testing it
English
0
0
0
7
Paylaş