IDOR – send a message on behalf of other user
I just found an IDOR in https://hello.dev.myhubs.net/. It allow attacker send a message on behalf of other user Step to reproduce: Admin: Create Room Attacker:
A Enthusiast Cyber Security Reseacher And Pentester
Hello! I’m Md Adnan Sami Bhuiyan, a fervent aficionado of the ever-evolving realm of cyber security.
My journey began with a keen interest in the vast domain of technology, which swiftly transitioned into a passion for cyber security. Today, I am proud to call myself a seasoned penetration tester, consistently pushing the boundaries of what’s possible in the quest to make the online world a safer place for all.
Throughout my career, I have had the privilege to wear multiple hats – from understanding the intricacies of various cyber threats to developing robust solutions that counteract them. Every day presents a new challenge, and with each challenge, I am reminded of the importance of staying one step ahead in this digital chess game.
When I’m not immersed in codes, scripts, or simulating cyber-attacks, you’ll find me delving into research, sharing knowledge with budding enthusiasts, or perhaps just enjoying a good tech podcast.
I am committed to not only improving and honing my skills but also to contributing to a community that’s larger than myself. Cyber security isn’t just about protection; it’s about innovation, adaptability, and anticipation. And I am here, playing my part, in this grand digital symphony.
Welcome to my corner of the web. Let’s navigate the complexities of the cyber realm together.
Here is a list of skills and competencies that are often valuable in the field of cybersecurity
I just found an IDOR in https://hello.dev.myhubs.net/. It allow attacker send a message on behalf of other user Step to reproduce: Admin: Create Room Attacker:
Target: Brave Software Title: New XSS vector in ReaderMode with %READER-TITLE-NONCE% Summary: Previously, script execution in ReaderMode pages was prohibited by CSP. However, three months
About Me I’m a Security Researcher at HackerOne, and in 2022, I ranked 60th globally on the HackerOne leaderboard. You can check my ranking here.
Target: U.S. Department of Defense Summary An External Service Interaction vulnerability (DNS and HTTP) was identified on the domain www.█████████. Burp Collaborator Results: DNS request
For Any Query Contact Here
Send Your Message here