alp1n3.eth

alp1n3.eth

alp1n3.eth

View all posts
Posts tagged with
file_upload(1)
Discover card cover image
Don't Tie AuthZ to a Referer Header...
Blog iconalp1n3.eth
Oct 8
Recently I saw a vulnerability that was very new to me. I've seen authN and authZ tied to some super random things in the past; ad tracking IDs, the literal username in a header, etc, but this one takes the cake for being weird to spot. It also highlights why the headers and their values need to be interrogated for both requests and responses. Starting the test there was a previous instance of an IDOR related to accessing uploaded files. The original vulnerability was pretty bad as it allowed...
alp1n3.eth

alp1n3.eth

Written by
alp1n3.eth 🌲alp1n3.eth 🌲

Ruminating on Web3, Security, and Privacy.

Subscribers<100
Posts18
Collects0

ÂŠī¸ 2025 Paragraph Technologies Inc

Privacy policyTerms of useDiscover great writing

alp1n3.eth
View all posts
Posts tagged with
file_upload(1)
Discover card cover image
Don't Tie AuthZ to a Referer Header...
Blog iconalp1n3.eth
Oct 8
Recently I saw a vulnerability that was very new to me. I've seen authN and authZ tied to some super random things in the past; ad tracking IDs, the literal username in a header, etc, but this one takes the cake for being weird to spot. It also highlights why the headers and their values need to be interrogated for both requests and responses. Starting the test there was a previous instance of an IDOR related to accessing uploaded files. The original vulnerability was pretty bad as it allowed...

Blog logo
Subscribe to alp1n3.eth

Stay updated by getting the latest posts delivered directly to your inbox.

Read it first