SHODAN - INSECURE DESIGN BROKEN ACCESS CONTROL

Currently reading:
 SHODAN - INSECURE DESIGN BROKEN ACCESS CONTROL

MixBanana

Member
LV
1
Joined
Oct 11, 2023
Threads
12
Likes
1
Awards
5
Credits
1,529©
Cash
0$
Affected Membership Packages: Academic Users, Small Business API Subscription, and up.
Filter query: vuln (Restricted), tag (Restricted)


[Image: 0*MBdGJGZzraruVQjx]

[Image: 0*wJ1cZEdzhnB-uPOO]

[Image: 0*9bLtdSSFBYm-KNxw]

[Image: 1*Iw4X1Xe0eoppn2Zk4r_5sA.png]



How It Works: The URL parameters can be tampered with to bypass access controls and retrieve information intended for higher-tier members. For example, using any restricted params in the URL and allows grouping the result set by IP addresses without the membership normally required for this action.

IDOR Links:
You can use any Shodan query filters without the need of registered Shodan account and also use the enterprise query filters such as ‘vuln’ or ‘tag’.

- https://www.shodan.io/search/facet?query=vuln%3Acve-2021-34473&facet=ip - https://www.shodan.io/search/facet?query=tag:honeypot&facet=ip - https://www.shodan.io/search/facet?query=tag:compromised&facet=ip

(You need to change the CVE you want to search in the URL and you can also to choose how you want to group the list with facet parameter. in this example I used to group them for IP’s.

Proof of Concept (PoC):

[Image: 0*oX43rcXdxjo2GeU4]

[Image: 0*0egrQK-NTQbr0N4s]

[Image: 1*i4D0cMd9otC-DONnlTcFBQ.png]


Credits: Sahar Shlichove.
Original post: https://medium.com/@mixbanana/shodan-idor-827ddac889b7
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Tips

Similar threads

Top Bottom