From User Enumeration to PII Exposure: Chaining Two APIs Into a $2,000 Bug
1 min read
Summary
Member-only story
From User Enumeration to PII Exposure: Chaining Two APIs Into a 2,000BugFreeArticleLink:[Clickforfree!](https://medium.com/@ehteshamulhaq198/from−user−enumeration−to−pii−exposure−chaining−two−apis−into−a−2−000−bug−adb9ed54ab30?sk=e894290830a0b49da7eb558af5f35c89)OneofthebiggestmistakesdevelopersmakeisthinkingthatiftwoAPIendpointsareindividuallyharmless,usingthemtogetherwillalsobeharmless.Unfortunately,thatisn’talwaystrue.Duringoneofmyrecentsecurityassessmentsontarget.com,Icameacrosswhatinitiallylookedlikeasimpleusersearchfeatureinsidethecompany’sAcademyplatform.Atfirstglance,therewasn’tanythingparticularlyexcitingaboutit.ItbehavedexactlyasIexpectedamessagingfeaturetobehave.OrsoIthought.AsIspentmoretimeunderstandinghowtheapplicationworked,thatseeminglyharmlessfeatureturnedintoachainedBrokenAccessControlvulnerabilitythatallowedalow−privilegedusertoenumerateplatformusersandexposesensitivepersonalinformationatscale.Thiseventuallyresultedina2,000 bounty, but more importantly, it reminded me why understanding how APIs interact is often more valuable than looking at them individually.
Looking Beyond the First Request
When I’m testing an application, I rarely stop after finding a single interesting response.