Sinisterly
IDOR And Information Disclosure found in boozt.com - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: IDOR And Information Disclosure found in boozt.com (/Thread-IDOR-And-Information-Disclosure-found-in-boozt-com)



IDOR And Information Disclosure found in boozt.com - Z0MBies - 08-03-2018

Title says all, i have successfully found an IDOR and Information Disclosure vulnerability in a company called 'Boozt' They are a REAL BIG company, all credits goes to me, cuz im the one who found and exploited this Smile Vuln has been patched by now, POC:

https://z0mbys.livejournal.com/1482.html


RE: IDOR And Information Disclosure found in boozt.com - mothered - 08-03-2018

Good find, a job well done In manipulating and bypassing the authorization and verification process.

When did the exploitation take place?


RE: IDOR And Information Disclosure found in boozt.com - Z0MBies - 08-03-2018

(08-03-2018, 11:44 AM)mothered Wrote: Good find, a job well done In manipulating and bypassing the authorization and verification process.

When did the exploitation take place?

First of all, TY Smile

Secondly, the exploitation took place a few months ago, the bug is already patched/fixed now.


RE: IDOR And Information Disclosure found in boozt.com - mothered - 08-03-2018

(08-03-2018, 12:15 PM)Z0MBies Wrote:
(08-03-2018, 11:44 AM)mothered Wrote: Good find, a job well done In manipulating and bypassing the authorization and verification process.

When did the exploitation take place?

First of all, TY Smile

Secondly, the exploitation took place a few months ago, the bug is already patched/fixed now.

You're welcome.

Seems they acted promptly with their corrective measures. Upon checking It out very briefly, It appears to have Insufficient (If any) Input data sanitization/filtering. I'll have an In depth look within the next couple of days.

Again, well done.


RE: IDOR And Information Disclosure found in boozt.com - Z0MBies - 08-03-2018

(08-03-2018, 03:21 PM)mothered Wrote:
(08-03-2018, 12:15 PM)Z0MBies Wrote:
(08-03-2018, 11:44 AM)mothered Wrote: Good find, a job well done In manipulating and bypassing the authorization and verification process.

When did the exploitation take place?

First of all, TY Smile

Secondly, the exploitation took place a few months ago, the bug is already patched/fixed now.

You're welcome.

Seems they acted promptly with their corrective measures. Upon checking It out very briefly, It appears to have Insufficient (If any) Input data sanitization/filtering. I'll have an In depth look within the next couple of days.

Again, well done.

Hey man, you mind reviewing my hacking guide? If so, please hit me on Discord:

PC_Box#5447


RE: IDOR And Information Disclosure found in boozt.com - Z0MBies - 09-20-2018

bumping this now for more people to see Smile