Tips and tricks for IDOR hunting. by @InonShkedy π
1. Object IDs in URLs tend to be less vulnerable. Try to put more effort on IDs in HTTP headers / bodies.
(my emphasis) Also, look for other non-ID parameters used as identifiers.
1. How I'm working on an AI - Cyber project.
2. A typical Day in the Life
3. Pay $0 => get nothing
4. Private bounties at @intigriti.
All this and more, in this week's blog π