And yes, I do see that the thermals are not optimal 🙃
And yes, I do see that the thermals are not optimal 🙃
Turns out, we can control the cache parameter, by forcing the victim to visit the link with our value!!
Turns out, we can control the cache parameter, by forcing the victim to visit the link with our value!!
But no... OP explains that it's not exploitable, because an attacker cannot guess the random cache key parameter :(
But no... OP explains that it's not exploitable, because an attacker cannot guess the random cache key parameter :(
Jokes aside, that's not the end of the story!
A fellow hunter asks some clarifying questions. Browser cache? Server side cache? Or maybe even a service worker?
Jokes aside, that's not the end of the story!
A fellow hunter asks some clarifying questions. Browser cache? Server side cache? Or maybe even a service worker?
OP reported an IDOR, gets paid $2,000, and then realizes it never was IDOR. It's just a cached response...
OP reported an IDOR, gets paid $2,000, and then realizes it never was IDOR. It's just a cached response...
Ange Albertini's talk. His work on file formats always was one of those "aha!" moments for me.
So it was really nice to see @angealbertini.bsky.social (corkami) back again at #38C3 <3
Ange Albertini's talk. His work on file formats always was one of those "aha!" moments for me.
So it was really nice to see @angealbertini.bsky.social (corkami) back again at #38C3 <3