• Zarobi@aussie.zone
    link
    fedilink
    English
    arrow-up
    19
    ·
    5 hours ago

    the API endpoint GET https://api/[.]clicktopray.org/user/users/%7Bid%7D will return user data for any account - not just your own account - so long as you supply a valid, five-digit user ID. It doesn’t perform any authorization check or ownership validation. “Just increment the number and get someone else’s data,” she wrote.

    This data includes users’ email addresses, first and last names, country, dates of birth, and whether the account has been deleted, and the API exposes all 719,517 accounts on the prayer site. “With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform,” the hacker explained. “One GET request per user. for i in range(1, 719518): scrape(). That’s it. That’s the exploit.”

    My God, that’s horrific. Plus it doesn’t even delete your data if you delete your account, it’s still vulnerable.

    • Zeoic@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 hour ago

      5 digit user ids, yet over 700k users? Im sure they must have gone up to 6 digits

      • Earthwormjim91@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        55 minutes ago

        Unless by “digit” they mean any alphanumeric.

        You’ve got a lot of options if you go to a 5 characters with letters.

        Which they’d kind of have to with 700k users if it’s 5 characters.

        If it’s case insensitive, you’ve got 60,000,000+ combinations, and if case sensitive then 916,000,000+ combinations.

      • Zarobi@aussie.zone
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        56 minutes ago

        They probably meant 6 digit and it was a typo. The rest of the article references 6 digits. If it’s just an integer (highly likely) it would go up to 10 digits or roughly 2 billion max users. My old coworkers and I used to joke that hitting INTEGER.MAX_VALUE for your customer ID is a good problem to have