client-side-security

2 articles
sort: new top best
clear filter
0 7/10

A bug bounty writeup demonstrating an account takeover vulnerability combining IDOR and weak encryption in a password reset function. The attacker decrypted Zlib-compressed tokens, discovered an Adler-32 checksum constraint, located a Transaction_Token endpoint via directory fuzzing, and automated exploitation to forge valid password reset links for arbitrary accounts.

Mayank Pandey CyberChef Zlib Adler-32 Python
mayank-01.medium.com · kh4sh3i/bug-bounty-writeups · 17 hours ago · details
0 6/10

A clickjacking vulnerability in Telegram's web client allowed attackers to iframe the application using sandboxed iframes to bypass frame-busting JavaScript, combined with blocking the app.css stylesheet to circumvent CSS-based visibility controls, enabling CSRF attacks and unauthorized account actions. The vulnerability was fixed by implementing server-side X-Frame-Options headers.

Telegram Mohamed A. Baset Pavel Durov Seekurity
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 17 hours ago · details