Summary
Link: https://techpsc.com/halloffame How This app work\s : For Non -Paid Student’s sets 1 -3 open freely, but selecting set 4 triggers a subscription payment prompt. How I Found Leaked APIs on the Android App: After breaking web app i tried to play with Android app too for which i decided to find the url by decompiling using MT Manager app but before that i once decided to check what would happen if i remove connection while taking QUiz , and it worked , the url was leaked there A similar leakage method applies to the Android version:
- Open the Android app and navigate to any quiz.
- Cut off your network connection (turn off Wi-Fi and mobile data). Get Sangharsha Upadhyaya’s stories in your inbox Join Medium for free to get updates from this writer.
- Attempt to load the quiz-the underlying API link will visibly leak right on the screen. Then i collected 3 more URL’s to find out the pattern How uuid and link is generated for QUiz for both Android and web after some time i broke it. After decoding And Bypassing the URL looked like : https://techpsc.com/xxxxx/xxxxx?quiz=xxxxxx4.json I was able to Run Unlimited QUiz as well to Download the required topic’s QUiz to show as a poc in my Google Colab . IMPACT : Full Payment feature bypass i.e Vulnerability allowed run test and give mock test without spending Rs 0. At Last: Thank you, Techpsc team, for being transparent, showing respect to researchers, and valuing our efforts!