Tags: oauth web
Rating: 5.0
/profile/1
to know the target is login as admin@footbook.meh
+
in email's name when sending messages
test+1@user.footbook.meh
will actually to test@user.footbook.meh
admin+whateveryouwant@footbook.meh
dropbox.com
gives unauthorized email.
extra_info
, don't ignore it!hitcon{why_s0_s3ri0u$!!}
hitcon{lfi_d03snt_sav3s_ou4_a$$}
hitcon{wow_n1c3_lf1}
hitcon{1_f00t_3q4l5_1_fl4g}
hitcon{CSRF_for_fun_and_pr0f1t!}
hitcon{f00t_1n_y0ur_m0uth?}
hitcon{f00tb00k_1z_d4_r3al_fB!!!}
hitcon{s3xy_f4c3b00k_>_<}
hitcon{f00tbook?_flagbook?_2333}