I Was Logged Out — But the API Still Trusted Me
作者在使用应用时误以为成功退出账户后感到自豪,但随后发现API仍在监控自己,意识到并未真正退出。这一漏洞并非显而易见,而是通过手动检查日志和请求头发现的,展示了细致观察的重要性。 2026-1-10 08:2:57 Author: infosecwriteups.com(查看原文) 阅读量:4 收藏

Iski

Free Link 🎈

Hey there!😁

Press enter or click to view image in full size

Image by AI

I logged out of the app and felt oddly proud of myself.
Closed the tab like my life was finally organized.
Leaned back in my chair thinking, okay, good session.

Then the API looked me straight in the face and said: “You never really left.” 😐🔥

How This Actually Began (No Fancy Exploits Yet)

This wasn’t one of those bugs where you instantly know you’ve hit gold.

Honestly? I was tired.

I had been hunting for hours. Lots of endpoints. Lots of nothing. The usual bug bounty mood where you start questioning whether every response is lying to you — or if you’re just seeing things.

So I slowed down.

No rush. No tools blasting requests. Just me, Burp, and curiosity.

Recon the Way Humans Actually Do It


文章来源: https://infosecwriteups.com/i-was-logged-out-but-the-api-still-trusted-me-85ebbe020544?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh