web cache deception on vdp program

4 days ago 11
BOOK THIS SPACE FOR AD
ARTICLE AD

Doorking

Just now

--

hello everyone

we are back again with a new article. for those who dont’t know me, I’am dorking and i love the field of discovering vulnerablilities

so let’s give our target a name target.com

first, i logged in to the site.then I went to the account

https://www.target.com/account

3. I tried hello.php but to no avail

https://www.target.com/account/hello.php

4. I tried again, this time with hello.js and hello.json and the result was seccessful. the end stores personal information

https://www.target.com/account/hello.js

https://www.target.com/account/hello.json

5.this way, the attacker will be able to stael the victim’s data when he opens the site

I hope you like this article.

https://x.com/LahsenNoua97684

https://www.linkedin.com/in/lahsen-nouali-435800303/

https://www.instagram.com/lahsen_nouali/

Read Entire Article