Insecure by Design: How a Mobile API Let Me Reset Anyone’s Password With Just a Phone Number
一位安全研究员深夜使用Burp Suite发现了一个API端点的逻辑漏洞,该漏洞源于匆忙部署且未经过测试。 2025-7-27 04:36:8 Author: infosecwriteups.com(查看原文) 阅读量:13 收藏

Iski

Free Link 🎈

Hey there!😁

Zoom image will be displayed

Image by AI

⚠️ Disclaimer: This blog is for educational purposes only. All vulnerabilities mentioned here have been responsibly disclosed to the organization involved. Don’t be a script kiddie. Be a responsible researcher. 🙏

It was 3:12 AM.

I was lying there, like most security researchers, contemplating if the fourth cup of coffee was a mistake or a stepping stone to glory. My eyes were burning, fingers jittery, and tabs — oh boy — 128 tabs open in Burp Suite like a DJ’s deck.

Some people count sheep to fall asleep.
I count open ports. 🐏🛜

And somewhere between api/v2/user/profile and my 7th screenshot of a 403 Forbidden, I struck gold. Or rather... I struck a leaky faucet of logic flaw in an API endpoint that screamed:

“I was made on a Friday evening, deploy-ready, zero test cases.”


文章来源: https://infosecwriteups.com/insecure-by-design-how-a-mobile-api-let-me-reset-anyones-password-with-just-a-phone-number-ba588ec384e5?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh