Everyone Tested the Login Page — I Tested the Logout Button Instead
文章描述了一位安全研究人员通过点击注销按钮意外进入管理员界面的经历,揭示了安全测试中忽视退出机制的问题。作者详细介绍了其使用的工具和方法来系统地进行漏洞探测。 2025-12-25 14:26:44 Author: infosecwriteups.com(查看原文) 阅读量:0 收藏

Iski

Free link 🎈

Hey there!😁

Press enter or click to view image in full size

Image by AI

Everyone in life checks how to enter.
Nobody checks how to leave.

We test job interviews, not resignations.
We test relationships, not breakups.

So naturally, while everyone was busy attacking /login,
I clicked Logout… and accidentally walked into admin land 😶‍🌫️

🔍 The Setup: Mass Recon Fatigue Is Real

This was not a lucky click.

This was the result of:

  • 200+ endpoints
  • 14 subdomains
  • Too much caffeine ☕
  • And a deep belief that boring endpoints hide the juiciest bugs

My recon stack (nothing fancy, just disciplined):

subfinder -d target.com -all | httpx -silent > live.txt
katana -list live.txt -jc -kf -fx > urls.txt

文章来源: https://infosecwriteups.com/everyone-tested-the-login-page-i-tested-the-logout-button-instead-3500c4168b67?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh