Hacking on a plane: Leaking data of millions and taking over any account
josephthacker.com | blog | #ai-security | #bug-bounty | #account-takeover | #data-exposure | #api-security | #idor | #writeup | #data-leak | #airline-wifi
Summary
Write-up of an IDOR in an in-flight WiFi provider's API: swapping the user_name, email_address, or customer_id parameter exposed tens of millions of users' data and enabled account takeover.
- Published
- Collected
Skip to content