api-enumeration

2 articles
sort: new top best
clear filter
0 5/10

Researcher discovered a full account takeover vulnerability by chaining multiple weaknesses: a password change endpoint that accepted null CSRF tokens and lacked proper validation, combined with a hidden 'uid' parameter discoverable via Param Miner that allowed changing arbitrary users' passwords without authentication. The vulnerability earned a $1000 bounty.

Mohsin Khan Param Miner James Kettle PortSwigger Burp Suite
mokhansec.medium.com · kh4sh3i/bug-bounty-writeups · 4 hours ago · details
0 6/10

Technical taxonomy of GraphQL attack classes including schema enumeration, batch query abuse, and resolver explosion attacks that are commonly missed by security tools.

medium.com · Ommkoli · 1 day ago · details