Insecure by Design: How a Mobile API Let Me Reset Anyone’s Password With Just a Phone Number
凌晨三点十二分,一名安全研究员在使用Burp Suite测试时发现了一个API端点的逻辑漏洞。该漏洞源于周五匆忙部署、未经过测试的代码。 2025-7-27 04:36:8 Author: infosecwriteups.com(查看原文) 阅读量:15 收藏

Iski

Free Link 🎈

Hey there!😁

Zoom image will be displayed

Image by AI

⚠️ Disclaimer: This blog is for educational purposes only. All vulnerabilities mentioned here have been responsibly disclosed to the organization involved. Don’t be a script kiddie. Be a responsible researcher. 🙏

It was 3:12 AM.

I was lying there, like most security researchers, contemplating if the fourth cup of coffee was a mistake or a stepping stone to glory. My eyes were burning, fingers jittery, and tabs — oh boy — 128 tabs open in Burp Suite like a DJ’s deck.

Some people count sheep to fall asleep.
I count open ports. 🐏🛜

And somewhere between api/v2/user/profile and my 7th screenshot of a 403 Forbidden, I struck gold. Or rather... I struck a leaky faucet of logic flaw in an API endpoint that screamed:

“I was made on a Friday evening, deploy-ready, zero test cases.”


文章来源: https://infosecwriteups.com/insecure-by-design-how-a-mobile-api-let-me-reset-anyones-password-with-just-a-phone-number-ba588ec384e5?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh