It's Steiner254
It's Steiner254

@Steiner254

14 Tweets 9 reads Nov 15, 2022
Day 0⃣6⃣/2⃣0⃣ -- [Delete/Deactivating An Account & Logout Vulnerabilities]
➡️ Day 6, Have You Ever Known That Deactivating & Logout Feature Can Be Hacked & Earn You Bounties?
➡️ Below are Tips & References (Feel Free To Share)🧵🧵👇👇
#BugBounty
#bugbountytips
#cybersecuritytips
1/n
IDOR — Let’s delete any account
@Bohr/idor-lets-delete-any-account-2926ae85ddbd" target="_blank" rel="noopener" onclick="event.stopPropagation()">medium.com
2/n
0 Click account delete CSRF
hacklido.com
3/n
CSRF in deleting an account
infosecwriteups.com
4/n
CSRF while deactivating an account
youtube.com
5/n
Authentication Bypass while deactivating an account using response manipulation
youtube.com
6/n
Lack of password in deleting an account
youtube.com
7/n
Email Not Completely Deleted after Deleting an account.
hackerone.com
8/n
Failure to invalidate session on logout
gaya3-r.medium.com
9/n
CSRF Leads to Logout any Loggedin user from their session
>> This is a P5..NO One Will Pay You Unless In A Pentest
bugcrowd.com
10/n
Improper Cache control on logout
youtube.com
11/n
CSRF in deleting an account
hackerone.com
12/n
CSRF in deleting an account
hackerone.com
n/n
Practice Makes Perfect!
Happy Hacking :)
See you here same time tomorrow!

Loading suggestions...