Web
breaking-parse-logic-gain-access-to-Nginx-API-read-write-upstreamsarrow-up-right
Information disclosure via API misconfigurationarrow-up-right
API Misconfiguration which leads to unauthorized access to ServiceDesk ticketsarrow-up-right
Secret Key Exposure in API Config Directoryarrow-up-right
Let’s know How I have explored the buried secrets in the Xamarin applicationarrow-up-right
Exploiting Application-Level Profile Semantics (APLS)arrow-up-right
API based IDOR to leaking Private IP addresses of 6000 businessesarrow-up-right
Exploiting API with AuthTokenarrow-up-right
JS is l0ve ❤️ $5K for Rest API Key. by Shivam Kamboj Dattana Mediumarrow-up-right
How An API Misconfiguration Can Lead To Your Internal Company Dataarrow-up-right
https://blogs.ad3sh.com/2020/06/api-endpoint-leads-to-account-takeover.htmlarrow-up-right
API secret key Leakage leads to disclosure of Employee’s Informationarrow-up-right
Bug Bounty: Broken API Authorizationarrow-up-right
Privilege Escalation using an API endpointarrow-up-right
Full Account Takeover via Changing Email And Password of any User through API Parametersarrow-up-right
Parameter Pollution issue in API resulting in $XXXarrow-up-right
Web Cache Deception to API endpoint attack using cached token headerarrow-up-right
How Misconfigured API leak user private information?arrow-up-right
Abusing internal API to achieve IDOR in New Relicarrow-up-right
Hey UserID x, what’s your secret token? Broken API enables me to leak/modify any users personal informationarrow-up-right
Fabric.io API permission apocalypse – Privilege Escalationsarrow-up-right
[NR Insights] IDOR - Modify the filter settings for any NR Insights dashboard through the internal_api endpointarrow-up-right
IDOR via internal_api “users” endpointarrow-up-right
Restricted users can view all account invoices, payment method details, PII of the account owner through zoura_api endpointsarrow-up-right
IDOR- Activate Mopub on different organizations- steal API token- Fabric.ioarrow-up-right
flash content type sniff vulnerability in api.slack.com, resolvedarrow-up-right
User guessing/enumeration at https://app.c2fo.com/api/password-reset, resolvedarrow-up-right
Mobile
https://abss.me/posts/fcm-takeover/arrow-up-right
https://web.archive.org/web/20210519175048/https://blog.dixitaditya.com/bypassing-google-maps-api-key-restrictions/arrow-up-right
https://web.archive.org/web/20210412151532/https://blogs.ad3sh.com/2020/06/api-endpoint-leads-to-account-takeover.htmlarrow-up-right
Hacking SMS API Service Provider of a Company Android App Static Security Analysis Bug Bounty POCarrow-up-right
Resources:
http://h1.nobbd.de/arrow-up-right
https://pentester.land/list-of-bug-bounty-writeups.htmlarrow-up-right
https://hackerone.com/hacktivity?querystring=apiarrow-up-right
https://raw.githubusercontent.com/besioo/hackerone/main/reports.csvarrow-up-right
Last updated 1 year ago