Tale of account takeover — Sensitive info Disclosure + Broken Access Control

Md Saqib
Md Saqib
Jul 10 · 4 min read
Leaking Auth_Token
Indirect Object Reference on auth leakage
Voila! Success!!

Welcome to a place where words matter. On Medium, smart voices and original ideas take center stage - with no ads in sight. Watch
Follow all the topics you care about, and we’ll deliver the best stories for you to your homepage and inbox. Explore
Get unlimited access to the best stories on Medium — and support writers while you’re at it. Just $5/month. Upgrade