Hacking Chess.com and Accessing 50 Million Customer Records
samcurry.net | blog | #bug-bounty | #account-takeover | #api-security | #mobile-security | #chess-com | #signature-bypass
Summary
Sam Curry recounts hacking Chess.com's mobile API: signed requests to api.chess.com seemed untamperable, until a flaw in how signatures were verified led to full takeover of any user account.
- Published
- Collected
Skip to content