Another day, Another IDOR vulnerability— $5000 Reddit Bug Bounty

Gaining unprivileged access to Reddit moderator logs

Roberto
InfoSec Write-ups
Published in
3 min readAug 6, 2022

--

Photo by Susan Q Yin on Unsplash

Here we go. Again.

IDOR, or insecure direct object reference, is a common yet insecure practice of referring to objects. By “insecure”, this simply means that it is easy to figure out what the pattern of how objects are named. For example, the…

--

--

Stanford alum, Software Engineer with a passion for CyberSec, Biotech, and Sustainability. Work with me at https://www.tidallabs.io/.