webProeasy

Lab 15 — ProfileHub — IDOR in User Profile API

hackadvisor

Task: Developer networking platform with public profiles and JSON API. Solution: Discovered IDOR in /api/users/{id}/profile endpoint that returns private data (including admin's private_notes with flag) without authorization check, while web interface properly filters sensitive fields.

$ ls tags/ techniques/
api_endpoint_discovery_via_javascript_analysisidor_exploitation_via_user_id_manipulationweb_vs_api_response_comparison

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups