Shadowing Practice: How I Made $30,000 Hacking Broken Access Control - Learn English Speaking with Video

Creando lección...
1
I've made over $30 ,000 from a single bug class broken access control on a single bug bounty program
2
and I know what you're thinking cool you found a bunch
3
of idols no the money didn't come from spaying low severe reports hoping
4
that one of them sticks it came from understanding the application better than the people who built it
5
and understanding how actually authentication works what does the app treat as sensitive action
6
and which features were built for roles I never was supposed to touch, then chaining them until a low turned into a critical.
7
In this video, I'm going to show you exactly how live with Real Labs, five bugs that I found and chained them into a full account takeover.
8
Stick around because the last one is the one that you will actually remember.
9
And real quick, if you're not familiar with broken access control bugs, it's very simple.
10
The app builds a wall around who's allowed to do what.
11
You are a normal user, so you shouldn't be able to read other people's data or hit an app in future or act as another account.
12
Broken access control is anytime that wall has a gap and that is it.
13
The whole game is finding those gaps and stacking them until we get a vulnerability that is worth reporting.
14
Now, I have actually built a lab so you can try it for yourself
15
and it is completely free over on Hacking Hub.
16
So everything I'm about to show you, you can practice the second this video ends.
17
If you want to go deeper, I've got a full broken access control course that breaks down this whole methodology, start to finish, and that link will be pinned in the comments.
18
All right, let me show you the app that we're hacking on today.
19
So this is the application that we have.
20
I know it looks super realistic.
21
Very proud of this lab that I put together.
22
You can log in quickly with the test account that you have right here, and you can just log in and it will take us to our application.
23
You can see we have a ton of different activities that we can do.
24
We can look at our recent activities, for example.
25
There are some data here there is records there is patients
26
there's teams you can see who is on your team
27
and you have staff
28
which surprisingly it says access denied we do not have access to do this
29
because our role as front desk does not have the permission to view this page
30
and we have users which is probably our different physicians site admins front desk
31
and so on so we have all of these
32
and each of these become a place where we want to attack
33
and find vulnerabilities obviously we have things like our profile and
34
so on and want to make sure we take a look at it
35
so this first vulnerability is your basic IDOR
36
and let me show you really quickly so we're going to go into records
37
and we're going to do our first encounter
38
and you can see this is like very basic numerical vulnerability
39
we can give it an ID for example 43 right here
40
and it shows us the data for another user
41
and every time we increment or decrease
42
that number it shows somebody else's data right this is what everyone thinks of
43
when it comes down to broken access control and a lot of times
44
if you're finding vulnerabilities like this one is either a dupe
45
or usually not a critical unless there is some PIIs or something that is screaming hey this should not be public.
46
This is where most people stop and just report these
47
and rack them up for low bounties
48
but don't worry we're going to come back to all these findings
49
that we're going to look at this video
50
and show you how we chain it but this is our first one super easy super simple you should already know this.
51
Now let's look at the next part of this this is the patient
52
if we click here and we do a search we can see
53
that it is sending a search query with whatever we put in here
54
so if I put in the word test for example
55
and somebody has the word test in it it will come
56
up my favorite thing to do here is just doing a single letter
57
so like a so everyone
58
that has the letter a in their name it will show up it's most common
59
and it works
60
but here's what a lot of people don't think about you will see things like clinic id
61
and most people are here to quickly maybe make it into a two you can see
62
that it's showing all of them and sometimes it may not actually work
63
but my favorite thing here is to do either a zero to see
64
if it does anything or just entirely removing that and by doing
65
so you can see that it shows everybody or every other clinics users
66
and all their different data births and email address and things like that
67
and it's one of the most common ways of finding vulnerabilities
68
where this is an eye door where I could see the data for a specific clinic
69
that is not mine which is seeing everybody's data think of this as
70
if you're doing an API call
71
and it's doing something like API v1 slash user slash ID you take
72
that id and either put that leading slash or do without it
73
and it leaks every user on that website sometimes you would do some bypasses there
74
so if there's an nginx rule for example
75
that just kind of stops it from happening you can do a percent 2f
76
and things like that that actually bypass it i have a whole video on
77
that i'll link it down below go watch on the channel
78
but that's just one of the other ones to look for
79
and this was another one that i looked at
80
because it just gave me every user's data on there
81
that i could actually enumerate and use as a part of my chain and later down the road.
82
So these are a little bit too simple, but I promise it's going to come full circle, but I want to kind of show it off before we put the whole chain together.
83
But let's go to the next one.
84
And that is our teams, which is also super interesting.
85
And let me show you why.
86
If I quickly click on team right here, this is supposed to allow me to see my own team's data, right?
87
So if I click on here and go to profile number one, if i go to profile number two number three
88
and this is number seven actually
89
so i can maybe do something like normal number three
90
that doesn't work in my case it allowed me on
91
that actual bug bounty program to enumerate everybody's data
92
but the interesting thing isn't the idol
93
that happens here is looking at what is being shown to
94
me on this screen again there was no api calls everything
95
that i was seeing was this it was a really ancient application
96
that was supposed to be internal but the cool thing was
97
and i would have probably missed it
98
and luckily with ai you You'll probably never miss this
99
if you're having AI actually look at all your data and your request.
100
But if you would have right -clicked on this link and you would have scrolled down to the bottom, you will see the data that is being shown to you that is visible on this screen and then some.
101
So you can see right here, I have the name right here with a password.
102
The password is PWFOX.
103
There is an email here.
104
There's a password hash.
105
The cool thing was on the password hash, it was this auth token and the MFA secret it because
106
if I have these two and
107
if you can find a way to use this auth token
108
and bypass the MFA then I can easily just take over an account
109
and become an admin and that's exactly what I did and
110
that is why this is so important for us
111
because now we only know everyone's user IDs now we know everyone's email addresses we found the vulnerability
112
that I could look at someone else's profile and
113
if I have the user ID I can go to
114
that user ID pull their password hash and maybe crack it
115
and then use the auth token at some point to see
116
if I can authorize myself into that account and
117
And that's why chaining vulnerabilities and multiple vulnerabilities together is more important than reporting them together.
118
Sure, you can report all those one by one.
119
Maybe you get 500 here, 500 there.
120
And each of those could be maybe a CVSS 5 or a 6, right?
121
And that's $2 ,000.
122
If you're finding a critical vulnerability that pays $5 ,000 to $10 ,000 and you put them all together in a bundle,
123
and you increase that CVSS score to a 9 or an 8 because of the impact that you have, then you're getting a whole lot of money for the same bucks.
124
So let me show you that in action really quick.
125
Now let's take a look at the last piece of this puzzle
126
and this is one that I wish I could make sense of it
127
but I couldn't but let's take a look either way.
128
So if we go to users here we can impersonate users
129
and if I click right here for example it will give us this access token
130
that we can take and we can log in just using this
131
but the key thing here was if I go to impersonate user number one
132
or this id number one which is the chief of medicine
133
which is more than likely the admin in this case it would tell us that this doesn't work.
134
So there's a couple of things here Let's first confirm that this functionality works.
135
So I'm going to grab this and we're going to put this at the end of the URL, go to another browser, and we're going to put this in there and boom, we're logged in as this doctor,
136
but this is the usual ID number two that we're looking at right about over here.
137
Let me go back.
138
It's this one.
139
We like this, but we love it more if we can become the admin, which probably has more functionality.
140
So what we want to do is, and this is what I showed you a little bit backwards in the original bug I noticed
141
that if I wanted to log in every time I did impersonate this token would change
142
so it's kind of impossible to guess how this is being created
143
but when I found the vulnerability within teams
144
when I would go to a profile and look at the source and at the bottom
145
this token existed I thought to myself maybe I could just use this to log in
146
and to my surprise Whereas if I actually swap it out and put that code in there,
147
it also logged in as that user based on the auth token that was leaked in their user profile.
148
Why that made sense and why it worked, I don't know.
149
Maybe the developers had a reason to do this, but it ended up working.
150
And this was one of the critical bugs, which helped me find more and more vulnerabilities by just unlocking more functionality.
151
So the key thing here wasn't just reporting all these bugs one by one.
152
I know this was really basic and really simple, but I want to kind of show the thought process of how do you map out an application?
153
How do you connect all these different functionalities?
154
How do you stop yourself from reporting a bug
155
and not just escalating it all the way through to get a critical finding?
156
In my case, I package all these into one simple bug and the title was something like IDOR leaks user auth token,
157
which then leads to account takeover using impersonation right that's a massive chain
158
that shows hey i found these different pieces of the puzzle
159
and these pieces of api i put them all together
160
and now i have a cvss of eight or nine
161
because it can arbitrarily take over any account of its own
162
and the cool thing was that
163
that endpoint for impersonation was also accessible without being logged in
164
so if you had someone's token
165
and you were not logged in it wouldn't check to see
166
if you're authorized so
167
if you had someone's token it was hardcoded it never changed
168
you always had a permanent account takeover on this application So that was it.
169
But before you go, let me just give you some really good advice, because what I just showed you, as I mentioned earlier, is the basic version.
170
First, don't make this your entire game.
171
What you just watched is a simple way to find broken access control and chain it.
172
It's a tool in your belt, not your entire focal point.
173
Only reach for it when it actually fits the company's threat model, because some programs genuinely just don't care about broken access control and you burn hours on bugs they'll never pay for.
174
So read the room first.
175
Two, the real money is in multi -org.
176
This is where it gets painful and that's exactly why it pays.
177
Picture a platform where every company it's its own tenant.
178
Now you have got to find a way to leak the org ID
179
and when it's a UUID instead of a nice clean integer, that's a bug all by itself.
180
Then you have to connect a user to that org.
181
Then maybe you can leak the address ID to pull every address.
182
Every one of those is a separate role that you have to find
183
and look you can report them one by one and get paid
184
but if you chain them and show
185
that you can leak every user's data on that platform in mass
186
that bounty is a completely different universe than the individual reports same bugs
187
but the chain is what changes
188
that number third once you get privest up to an admin
189
or someone with more access do not stop there there are
190
two things you want to explore one hit all of those newly discovered endpoints and test them for authorization.
191
Honestly, this is stupid easy now because you have something like Claude that can map him out for you in minutes.
192
But two, this is the important one and it's a little bit controversial.
193
Start looking for deeper bugs.
194
It's technically out of scope because you were never supposed to have an admin account in the first place.
195
But if you're sitting in that admin panel and you see a functionality that smells like RCE, SSRF, or even SQL injection,
196
my take is try it and ask for forgiveness later rather than walking away wondering what if.
197
Most companies actually appreciate these reports.
198
Just don't be too aggressive with it and use your judgment.
199
And one last thing, you'll probably notice I mentioned cloud and AI a few times during this video.
200
I've been messing with building a custom skill that actually hunts for broken access control bugs for me.
201
So drop a comment down below with the word AI maybe
202
if you want to see me actually build one out and let it loose on some of these labs.
203
If enough of you wanted, then that may be one of the next videos in the future
204
but all right that's it i hope you enjoyed this video the course is pinned in the comments down below
205
and if you haven't already make sure you hit
206
that subscribe button becoming a homie like this video drop a comment
207
and i'll see you all in next week's video peace

Why This Video Is Perfect for Your Speaking Practice

This video isn’t just about hacking—it’s a goldmine for English learners. The speaker uses conversational language, natural pauses, and relatable explanations, making it ideal for practicing the shadowing technique. Whether you’re new to shadowing or refining your skills, the mix of technical terms and casual speech helps you adapt to real-world communication. Plus, the step-by-step storytelling keeps you engaged, so you’ll forget you’re practicing!

Breaking Down Natural Speech Patterns

Let’s look at a few lines that sound like real conversation. First: “I know what you’re thinking—cool, you found a bunch of idols. No, the money didn’t come from spaying low severe reports hoping that one of them sticks.” The pause after “thinking” and the casual “No” mimic how we correct others in daily talk. Next: “Stick around because the last one is the one that you will actually remember.” Phrases like “Stick around” and “actually remember” are common in friendly explanations, showing how to keep a listener hooked. Finally: “This is what everyone thinks of when it comes down to broken access control.” “When it comes down to” is a natural way to simplify a topic, a phrase you can use in any discussion. These lines prove that even technical content can sound conversational—key for fluent speaking.

A Simple Shadowing Routine to Try

Ready to practice? Use the shadowing technique with this video in 3 steps. First, watch a 30-second clip and focus on the speaker’s rhythm and intonation. Then, play the clip again and repeat each sentence immediately after, matching their speed and tone—this is where “shadowspeak” (copying speech like a shadow) works its magic. Finally, record yourself and compare it to the original. Notice if you paused in the right places or stressed the same words. Do this daily, and you’ll start to sound more natural in no time. Remember, the goal isn’t perfection—it’s getting comfortable with how English flows. Try it with the part about IDOR vulnerabilities, and you’ll see how shadowing turns complex dialogue into usable skills!

¿Qué es la Técnica de Shadowing?

Shadowing es una técnica de aprendizaje de idiomas respaldada por la ciencia, desarrollada originalmente para la formación de intérpretes profesionales y popularizada por el políglota Dr. Alexander Arguelles. El método es simple pero poderoso: escuchas audio en inglés nativo y lo repites en voz alta de inmediato, como una sombra que sigue al hablante con solo 1-2 segundos de retraso. A diferencia de la escucha pasiva o los ejercicios de gramática, el shadowing obliga a tu cerebro y músculos de la boca a procesar y reproducir simultáneamente patrones de habla reales. Las investigaciones muestran que mejora significativamente la precisión de la pronunciación, la entonación, el ritmo, el habla conectada, la comprensión auditiva y la fluidez al hablar, convirtiéndola en una de las metodologías más efectivas para la preparación del IELTS Speaking y la comunicación en inglés en el mundo real.

Técnica de shadowing: lee la guía completa paso a paso →