--

Yeah, both from the same program. If you are talking about article: Email and home address disclosure using unauthenticated API endpoint worth $500 then $500 because the booking_id is random hash which is not bruteforcable and there is no API to fetch other users booking_id. I found few booking ID in wayback url.

--

--

the_unlucky_guy
the_unlucky_guy

Written by the_unlucky_guy

Security Engineer | Never Forgive Never Forget

No responses yet