When APIs Trust Too Much: Chat Impersonation through Broken Auth [Bug bounty write-up] — Kullai :)
Hey everyone, Kullai here! I’m back with another interesting finding this time, it’s a fun one. I discovered a way where an attacker could impersonate a victim and chat as them directly to them yep, you read that right! Let’s dive into this …..
There was an Organization and Every organization has Multiple roles. In our Orgnization there are two Super Admins and multiple Low privileged users. Two Super Admins Namely Apple Tester-1 and Apple Tester created a Secret Channel and they are chatting .
In the same Organization there is an member called kullaiswamy107 Low in the name itself you can see he is a Low privileged user but he is a malicious attacker as well.
When He opened the burp and tried to chat with other users in the same Organization he found one suspicious request in his burp.
There are some ID’s in the Request those ID’s are Organization ID’s and same org members can view that [No Complexity]
As a member of the same Organization Literally everyone can access this endpoint and they can see Full Org Channel ID’s LoL !
Straight forward IDOR we can check [It is vulnerable off-course]
What Attacker do is try to chat to any other member in the same org and capture the request and in that request he simply changes the channel ID .
You can see in the above Vulnerable POST request attacker changed the channel ID with Super Admin’s secret channel ID and Lol Attacker managed to chat in the Two Super Admins Channel and the main thing is he was able to chat as a Apple Tester-1 [one of the Super Admin] [Integrity at it’s peak]
And yes They Accepted it and paid $500 [very low] I believe and fixed it .
Follow me for more content:
LinkedIn | Twitter | Instagram
Thanks for reading!!
Your Kullai :)
