Session not expired When logout [partners.uber.com]
It's funny, when i can reproduce it 4 days ago and make some video, the team said we’re unable to reproduce this issue following the steps you provided. it's i copy - paste with my report on hackerone
Hi,
Summary
partners.uber.com website is not expiring the user's session immediately after logout.
when user logout, the session not expired, and still can send request and the server respond response with OKAY
Steps to Reproduce:
the team it's fixed this issue, and say this is was unvalidated issue.but the team won't to disclose report, finally after few roast, team agree to disclose.
i try to contact hackerone team with support, because when i want to call hackerone team to my report, there's no option on my report.
Last word : dont forget to make some video when you want to report it guys :)
Summary
partners.uber.com website is not expiring the user's session immediately after logout.
when user logout, the session not expired, and still can send request and the server respond response with OKAY
Steps to Reproduce:
- Log into the website - partners.uber.com
- Capture any request. For ex, profile edit page using burp proxy.
- Logout from the website.
- Replay the request captured in step 2 and notice it displays the proper response.
the team it's fixed this issue, and say this is was unvalidated issue.but the team won't to disclose report, finally after few roast, team agree to disclose.
i try to contact hackerone team with support, because when i want to call hackerone team to my report, there's no option on my report.
Last word : dont forget to make some video when you want to report it guys :)
Comments
Post a Comment