Skip to main content

Posts

Showing posts from January, 2022

How i found “Broken Access Control Through out-of-sync setup” and got $1000

Hello everyone ! , Hope you all are doing well, I would like to share my “Broken Access Control Through out-of-sync setup” What is BAC (Broken Access Control Attack) ? Broken Access Control is when an application does not thoroughly restrict user permissions for appropriate access to administrative functionality. The consequences associated to broken access control may include viewing of unauthorized content, modification or deletion of content, or full application takeover. A few examples of common access control vulnerabilities are role based access, poor password management, insecure Id’s, forced browsing past access control checks, path traversal, file permissions, and client side caching. Recon: Gathering information about your target is the golden key to reaching weak points, so I care a lot about the stage of collecting information and i Really enjoy the logical vulnerabilities and take great care of the functionality of the site , My target it was a private program on hackerone...