RE: 10 Year Old Awarded 10k For Instagram Vulnerability 05-06-2016, 01:27 AM
#11
(05-06-2016, 01:10 AM)Pirate Wrote: Did they ever reveal how the vuln was performed? (Since its patched now obviously)
If it has to do with an API and anyone being able to delete comments, it's safe to assume it was probably an insecure direct object reference. If it's not, my second best guess would be something to do with sessions. Neither would be hard to do or create a PoC for, it's just a matter of who gets to it first.

![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)




















![[Image: Hotline_Miami_2_banner.png]](http://www.gamegrin.com/files/images/news/2013/Hotline_Miami_2_banner.png)





![[Image: JchOGM.png]](http://imageshack.com/a/img923/2406/JchOGM.png)