Unauthorized Unsubscription and Message of Employee
文章描述了一次漏洞赏金狩猎经历,作者通过子域名枚举、Waybackurls数据和随机探索的方法寻找目标漏洞。在分析某网站的静态订阅页面时尝试XSS攻击未果后,发现了员工取消订阅功能中的未授权消息发送漏洞。 2025-9-25 08:23:11 Author: infosecwriteups.com(查看原文) 阅读量:22 收藏

Unsubscribing Employee and Sending Unauthorized Message

SIDDHANT SHUKLA

Read for Freee..ee.e

kakashi

🐺Hunters,

I hope my write-ups are easy to understand with helpful tips and learnings for you so that you can also get your bug using the same thing.

If you learned something from my articles you can send appreciation with

50 claps and comment your thoughts

My Hunting

My recon usually follows three things subdomain enumeration, waybackurls data and just random Hunting. I am telling you this because I got many DMs on instagram like what kind of Methodology or pdf check I followed, I don’t have any checklist and it’s not bad to follow a checklist.
My bug bounty tip for you:

Understand your Target.

Introduction

I started hunting on my primary target, and actually lously looking at my target’s waybackurls data to get something interseting so that I can start hunting. After sometime one url which is basically an static page with usual Subscribe Me button to get notifications caught my attention.
As a hunter, I started with XSS payloads to get an alert but the…


文章来源: https://infosecwriteups.com/unauthorized-unsubscription-employee-bf36d81e3e8d?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh