3 ms·
Url based session ids led to me finding a quite substantial security hole in a popular games mod website that allowed me to modify and delete my mods without be
by Lockyy 14y ago
Url based session ids led to me finding a quite substantial security hole in a popular games mod website that allowed me to modify and delete my mods without being logged in. Also was able to view my own download history, potentially very embarrassing for some people.
So yes, I can testify that in this websites case their use of session ids in the url during a website renovation (where people were posting their urls on the forums to help fix bugs) led to a lot of people being made vulnerable.
I just wish they'd at least thanked me for informing them of the vulnerability...