Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


IDOR And Information Disclosure found in boozt.com filter_list
Author
Message
IDOR And Information Disclosure found in boozt.com #1
Title says all, i have successfully found an IDOR and Information Disclosure vulnerability in a company called 'Boozt' They are a REAL BIG company, all credits goes to me, cuz im the one who found and exploited this Smile Vuln has been patched by now, POC:

https://z0mbys.livejournal.com/1482.html
(This post was last modified: 12-18-2018, 09:48 PM by Z0MBies.)
Love to love, Hate to hate

Reply

RE: IDOR And Information Disclosure found in boozt.com #2
Good find, a job well done In manipulating and bypassing the authorization and verification process.

When did the exploitation take place?
[Image: AD83g1A.png]

Reply

RE: IDOR And Information Disclosure found in boozt.com #3
(08-03-2018, 11:44 AM)mothered Wrote: Good find, a job well done In manipulating and bypassing the authorization and verification process.

When did the exploitation take place?

First of all, TY Smile

Secondly, the exploitation took place a few months ago, the bug is already patched/fixed now.
(This post was last modified: 08-03-2018, 12:16 PM by Z0MBies.)
Love to love, Hate to hate

Reply

RE: IDOR And Information Disclosure found in boozt.com #4
(08-03-2018, 12:15 PM)Z0MBies Wrote:
(08-03-2018, 11:44 AM)mothered Wrote: Good find, a job well done In manipulating and bypassing the authorization and verification process.

When did the exploitation take place?

First of all, TY Smile

Secondly, the exploitation took place a few months ago, the bug is already patched/fixed now.

You're welcome.

Seems they acted promptly with their corrective measures. Upon checking It out very briefly, It appears to have Insufficient (If any) Input data sanitization/filtering. I'll have an In depth look within the next couple of days.

Again, well done.
[Image: AD83g1A.png]

Reply

RE: IDOR And Information Disclosure found in boozt.com #5
(08-03-2018, 03:21 PM)mothered Wrote:
(08-03-2018, 12:15 PM)Z0MBies Wrote:
(08-03-2018, 11:44 AM)mothered Wrote: Good find, a job well done In manipulating and bypassing the authorization and verification process.

When did the exploitation take place?

First of all, TY Smile

Secondly, the exploitation took place a few months ago, the bug is already patched/fixed now.

You're welcome.

Seems they acted promptly with their corrective measures. Upon checking It out very briefly, It appears to have Insufficient (If any) Input data sanitization/filtering. I'll have an In depth look within the next couple of days.

Again, well done.

Hey man, you mind reviewing my hacking guide? If so, please hit me on Discord:

PC_Box#5447
Love to love, Hate to hate

Reply

RE: IDOR And Information Disclosure found in boozt.com #6
bumping this now for more people to see Smile
Love to love, Hate to hate

Reply