bars
Biscuit's Bug Bounty Playbook
search
circle-xmark
โ
Ctrl
k
copy
Copy
chevron-down
Bug Bounty Reports & Articles
2๏ธโฃ
IDOR (Indirect Object Reference)
Chaining IDOR and Host Header can takeover 18 Million of users account
Medium
chevron-right
($$$$) Critical IDOR Vulnerability Leads to User Information Disclosure
Medium
chevron-right
IDOR at Election Commission Website
Medium
chevron-right
Acronis disclosed on HackerOne: IDOR vulnerability (Price...
HackerOne
chevron-right
GitLab disclosed on HackerOne: Add and Access to Labels of any...
HackerOne
chevron-right
Automattic disclosed on HackerOne: IDOR leads to Edit Anyone's...
HackerOne
chevron-right
Reddit disclosed on HackerOne: IDOR allows an attacker to modify...
HackerOne
chevron-right
HackerOne disclosed on HackerOne: IDOR - Delete all Licenses and...
HackerOne
chevron-right
HackerOne disclosed on HackerOne: Insecure Direct Object Reference...
HackerOne
chevron-right
https://bepractical.tech/blogs/all-about-idor/
bepractical.tech
chevron-right
How I (Ethically) Hacked My College Portal with a JWT Tokenโโโand Reported It Responsibly
Medium
chevron-right
Previous
dependency confusion vulnerability
chevron-left
Next
Leaks & Disclosure (PII, API Key, etc)
chevron-right
Last updated
4 months ago
sun-bright
desktop
moon
sun-bright
desktop
moon