Biscuit's Bug Bounty Playbook
Ctrl
K
Copy
Bug Bounty Reports & Articles
2๏ธโฃ
IDOR (Indirect Object Reference)
Chaining IDOR and Host Header can takeover 18 Million of users account
Medium
IDOR at Election Commission Website
Medium
Acronis disclosed on HackerOne: IDOR vulnerability (Price...
HackerOne
GitLab disclosed on HackerOne: Add and Access to Labels of any...
HackerOne
Automattic disclosed on HackerOne: IDOR leads to Edit Anyone's...
HackerOne
Reddit disclosed on HackerOne: IDOR allows an attacker to modify...
HackerOne
HackerOne disclosed on HackerOne: IDOR - Delete all Licenses and...
HackerOne
HackerOne disclosed on HackerOne: Insecure Direct Object Reference...
HackerOne
All about IDOR
BePractical Blogs
How I (Ethically) Hacked My College Portal with a JWT Tokenโโโand Reported It Responsibly
LegionHunters
Previous
dependency confusion vulnerability
Next
Leaks & Disclosure (PII, API Key, etc)
Last updated
1 month ago