You don’t always have to predict the identifier #bugbounty #bugbountytips #bugbountyhunter

preview_player
Показать описание

This video is a part of the case study of 187 IDOR bug bounty reports. In this part, I take a look at what types of IDs were used by vulnerable applications and, where relevant, how did the hunters predict them.
Рекомендации по теме
Комментарии
Автор

I think the ideas here is you can get your hand on private videos which was public before and posted on social meda / etc.. so I think this is the reason why it was accepted. Otherwise account IDs isn't something that people share on platforms so its kinda impossible to have impact unless you convinced the triage that if someone in the future found a bug that leaks the ID then he'll use this endpoint as a chain

expert