Unbelievable that REST APIs of Verizon carried a user-id param that could simply be fuzzed and not tied to auth randywestergren.com/critical…
3
16
3
Replying to @cschneider4711
@cschneider4711 @kaffeecoder Also, they used HTTP, not HTTPS :-)

Jan 18, 2015 · 7:45 PM UTC

2