Brut Security
15.2K subscribers
965 photos
76 videos
292 files
1.01K links
DM: @wtf_brut
🛃WhatsApp: https://wa.link/brutsecurity
🈴Training: https://brutsecurity.com
📨Mail: info@brutsec.com
Download Telegram
💡 IDOR Bypass Bug Bounty Tip

Sometimes APIs behave unexpectedly when multiple IDs are passed together.

🔍 Scenario
• Victim’s ID: 5200
• Attacker’s ID: 5233

🚫 GET /api/users/5200/info → Access Denied
GET /api/users/5200,5233/info → Bypass Successful

📌 Always test for comma-separated, array-style, or batch ID parameters when hunting for IDOR!

#bugbountytips #bugbounty #infosec #cybersecurity #api #IDOR #pentesting #bugbountyTips
🔥28👍1210👏2