How I dumped users’ passports from the exchange
hackenproof.com | blog | #bug-bounty | #vulnerability-research | #data-exposure | #brute-force | #writeup | #crypto-exchange | #kyc
Summary
A critical KYC flaw on a crypto exchange: predictable Unix-timestamp filenames and public storage let a researcher brute-force file URLs and dump users' passports.
- Published
- Collected
Skip to content