In-app reader
I’m curious about people’s real-world experience with IDOR/BOLA in bug bounty programs. Do you encounter them frequently while hunting, or are they relatively rare on mature bounty programs? Also, are most of the ones you find basic object-ID manipulation, or do you usually encounter more complex cases involving APIs, roles/permissions, business logic, JWTs, etc.? I’d be especially interested in hearing roughly how many IDOR/BOLA findings you’ve made compared to other vulnerability types. submitted by /u/Much_Exchange_6101 [link] [comments]
Discussion
Sign in to join the discussion.
Keep reading
Optional: create a free account to save items, track programs, and sync across web + app. Reading stays free.