Abusing URL Shortners for fun and profit

Sicksec
InfoSec Write-ups
Published in
4 min readJul 14, 2022

--

Photo by Boitumelo Phetla on Unsplash

Hello Security Researchers

Have you ever encountered a bug where it’s hard to show impact due to the lack of enumeration of a certain value of a parameter ?
Well if yes, In this writeup I will talk about how you can find and abuse URL shortners to ATO or Information disclosure

--

--

I’m an Enthusiast bug bounty Hunter part of Synack Red Team Member, Here to make Internet Safer and talk about my findings