Terminal

// Tag02 entries

web

Everything filed under web, newest first.

Write-ups

[TARGET]
HackerOne
[SEVERITY]
critical
[CLASS]
Vuln & CVE

An IDOR that became account takeover through OAuth

The object reference was only half of it. This follows the OAuth binding that trusted a client-supplied identifier, and the full takeover it allowed.

[TOOLS]burppython

1 min

[TARGET]
HackTheBox
[DIFFICULTY]
Easy
[CLASS]
CTF & Labs

SSRF to RCE on Sau, and why the forgery worked

How an unauthenticated request-basket service reaches an internal Maltrail instance, and why the loopback restriction never applied to it at all.

[TOOLS]nmapburpcurl

1 min