Skip to content

Commit 6336844

Browse files
authored
Update 2025-09-10-idor-zseano.md
1 parent e32dc5a commit 6336844

File tree

1 file changed

+1
-2
lines changed

1 file changed

+1
-2
lines changed

_posts/2025-09-10-idor-zseano.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -35,10 +35,9 @@ Then I found a path in the JS file where it appears that the web application ret
3535

3636
![3](https://github.com/T3chnocr4tx/T3chnocr4tx.github.io/assets/82b31b0e-a77c-40aa-aa7a-83a686533089)
3737

38-
So, I checked my cookies and saw some long value in the user ID, but how can this be guessable?
38+
- So, I checked my cookies and saw some long value in the user ID, but how can this be guessable?
3939
But, you know, thinking in my head, let me just copy this path and add a numerical value. then it appeared I could see some information.
4040

41-
![test](https://github.com/user-attachments/assets/79a5e956-b415-45dd-82e9-817f1bce64f2)
4241

4342
Then I sent the request to automate enumeration, thinking maybe I could get other users' information. Then I found 7 people. Wow, what an IDOR!
4443

0 commit comments

Comments
 (0)