nitter
Christian Schneider
@cschneider4711
18 Jan 2015
Unbelievable that REST APIs of Verizon carried a user-id param that could simply be fuzzed and not tied to auth
randywestergren.com/critical…
3
16
3
Stefan Tilkov
@stilkov
18 Jan 2015
Replying to
@cschneider4711
@cschneider4711
@kaffeecoder
Also, they used HTTP, not HTTPS :-)
Jan 18, 2015 · 7:45 PM UTC
2