Unauthorized Unsubscription and Message of Employee
作者分享了漏洞赏金狩猎经验,通过子域名枚举、Wayback URLs数据和随机狩猎寻找目标。在一次狩猎中,他发现某网站静态页面的订阅功能存在CSRF漏洞,并利用该漏洞实现员工取消订阅及发送未经授权的消息。 2025-9-25 08:23:11 Author: infosecwriteups.com(查看原文) 阅读量:18 收藏

Unsubscribing Employee and Sending Unauthorized Message

SIDDHANT SHUKLA

Read for Freee..ee.e

kakashi

🐺Hunters,

I hope my write-ups are easy to understand with helpful tips and learnings for you so that you can also get your bug using the same thing.

If you learned something from my articles you can send appreciation with

50 claps and comment your thoughts

My Hunting

My recon usually follows three things subdomain enumeration, waybackurls data and just random Hunting. I am telling you this because I got many DMs on instagram like what kind of Methodology or pdf check I followed, I don’t have any checklist and it’s not bad to follow a checklist.
My bug bounty tip for you:

Understand your Target.

Introduction

I started hunting on my primary target, and actually lously looking at my target’s waybackurls data to get something interseting so that I can start hunting. After sometime one url which is basically an static page with usual Subscribe Me button to get notifications caught my attention.
As a hunter, I started with XSS payloads to get an alert but the…


文章来源: https://infosecwriteups.com/unauthorized-unsubscription-employee-bf36d81e3e8d?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh