signature-bypass

1 article
sort: new top best
clear filter
0 7/10

A SQL injection vulnerability achieved through double-quote injection in a signed API endpoint. The attacker discovered the MD5 signature generation method was documented, leaked the SecretKey, and exploited it to bypass signature validation and perform time-based blind SQL injection attacks resulting in a CVSS 10.0 critical vulnerability with $2000 bounty payout.

Ahmed ElTijani HackerOne SUDOROOT sqlmap
medium.com · kh4sh3i/bug-bounty-writeups · 22 hours ago · details