
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Guge&#39;sBlog</title>
      <link>https://gugesay.com/blog</link>
      <description>骨哥说事公众号首发地</description>
      <language>zh-CN</language>
      <managingEditor>undefined (Guge)</managingEditor>
      <webMaster>undefined (Guge)</webMaster>
      <lastBuildDate>Wed, 21 Aug 2024 01:48:17 GMT</lastBuildDate>
      <atom:link href="https://gugesay.com/tags/idor/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://gugesay.com/blog/idor之如何打破订阅限制</guid>
    <title>IDOR之如何打破订阅限制</title>
    <link>https://gugesay.com/blog/idor之如何打破订阅限制</link>
    undefined
    <pubDate>Wed, 21 Aug 2024 01:48:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【2000】利用重置密码实现帐户接管</guid>
    <title>【$2000】利用重置密码实现帐户接管</title>
    <link>https://gugesay.com/blog/【2000】利用重置密码实现帐户接管</link>
    undefined
    <pubDate>Thu, 26 Sep 2024 07:58:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category><category>重置密码</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【2000】由于缓存配置错误导致授权绕过</guid>
    <title>【$2000】由于缓存配置错误导致授权绕过</title>
    <link>https://gugesay.com/blog/【2000】由于缓存配置错误导致授权绕过</link>
    undefined
    <pubDate>Thu, 22 Aug 2024 06:29:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bypass</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【6000】firefox-高危漏洞披露</guid>
    <title>【$6,000】Firefox 高危漏洞披露</title>
    <link>https://gugesay.com/blog/【6000】firefox-高危漏洞披露</link>
    undefined
    <pubDate>Wed, 04 Jun 2025 01:05:18 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>firefox</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【h1最新披露】ups公司管理员身份验证绕过导致帐户</guid>
    <title>【H1最新披露】UPS公司管理员身份验证绕过导致帐户接管案例</title>
    <link>https://gugesay.com/blog/【h1最新披露】ups公司管理员身份验证绕过导致帐户</link>
    undefined
    <pubDate>Mon, 08 Jul 2024 08:54:08 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>idor</category><category>ups</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【奖金5000】将任意无主手机号码添加到我的facebook账户</guid>
    <title>【奖金$5000】将任意无主手机号码添加到我的Facebook账户</title>
    <link>https://gugesay.com/blog/【奖金5000】将任意无主手机号码添加到我的facebook账户</link>
    undefined
    <pubDate>Fri, 11 Feb 2022 02:19:05 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>facebook</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【白帽狩猎日记】一个支付逻辑漏洞，爽赚-9000-赏金</guid>
    <title>【白帽狩猎日记】一个支付逻辑漏洞，怒赚 $9000 赏金</title>
    <link>https://gugesay.com/blog/【白帽狩猎日记】一个支付逻辑漏洞，爽赚-9000-赏金</link>
    undefined
    <pubDate>Tue, 29 Apr 2025 02:44:03 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>idor</category><category>PayU</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/价值-1000-美元的账户接管</guid>
    <title>价值 1000 美元的账户接管</title>
    <link>https://gugesay.com/blog/价值-1000-美元的账户接管</link>
    undefined
    <pubDate>Wed, 24 Aug 2022 02:58:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/具有邀请功能的账户劫持思路</guid>
    <title>具有邀请功能的账户劫持思路</title>
    <link>https://gugesay.com/blog/具有邀请功能的账户劫持思路</link>
    undefined
    <pubDate>Thu, 30 Nov 2023 02:14:12 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用Auth0错误配置，获得$1600赏金奖励</guid>
    <title>利用Auth0错误配置，获得$1600赏金奖励</title>
    <link>https://gugesay.com/blog/利用Auth0错误配置，获得$1600赏金奖励</link>
    undefined
    <pubDate>Mon, 22 Apr 2024 08:26:59 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API</category><category>Auth0</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用未授权的密码重置实现完全帐户接管</guid>
    <title>利用未授权的密码重置实现完全帐户接管</title>
    <link>https://gugesay.com/blog/利用未授权的密码重置实现完全帐户接管</link>
    undefined
    <pubDate>Tue, 27 May 2025 06:21:36 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>idor</category><category>白帽故事</category><category>账户接管</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/发现关键漏洞获得-4000-赏金奖励</guid>
    <title>发现关键漏洞获得 $4,000 赏金奖励</title>
    <link>https://gugesay.com/blog/发现关键漏洞获得-4000-赏金奖励</link>
    undefined
    <pubDate>Wed, 11 Dec 2024 01:17:11 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>subdomain</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/另一枚价值3133-7的google-idor漏洞</guid>
    <title>另一枚价值$3133.7的Google IDOR漏洞</title>
    <link>https://gugesay.com/blog/另一枚价值3133-7的google-idor漏洞</link>
    undefined
    <pubDate>Wed, 29 Sep 2021 02:11:32 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Google</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在阅读了220份idor漏洞报告后的心得体会</guid>
    <title>在阅读了220份IDOR漏洞报告后的心得体会</title>
    <link>https://gugesay.com/blog/在阅读了220份idor漏洞报告后的心得体会</link>
    undefined
    <pubDate>Fri, 25 Feb 2022 06:20:41 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何从已披露的漏洞报告中重新发现新的漏洞</guid>
    <title>已修复漏洞？如何绕过并再次利用！</title>
    <link>https://gugesay.com/blog/如何从已披露的漏洞报告中重新发现新的漏洞</link>
    undefined
    <pubDate>Thu, 14 Nov 2024 07:22:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何获得免费的linkedin-premium会员资格</guid>
    <title>一次白嫖LinkedIn Premium会员资格的经历</title>
    <link>https://gugesay.com/blog/如何获得免费的linkedin-premium会员资格</link>
    undefined
    <pubDate>Thu, 07 Sep 2023 08:15:25 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>Linkedln</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/巧妙利用业务逻辑漏洞，实现google帐户接管</guid>
    <title>巧妙利用业务逻辑漏洞，实现Google帐户接管</title>
    <link>https://gugesay.com/blog/巧妙利用业务逻辑漏洞，实现google帐户接管</link>
    undefined
    <pubDate>Thu, 08 Aug 2024 01:41:18 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Google</category><category>idor</category><category>otp</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/巧妙利用本地存储漏洞，轻松登录他人直播-app-账户</guid>
    <title>巧妙利用本地存储漏洞，轻松登录他人直播 App 账户</title>
    <link>https://gugesay.com/blog/巧妙利用本地存储漏洞，轻松登录他人直播-app-账户</link>
    undefined
    <pubDate>Wed, 29 May 2024 03:25:19 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>Local Storage</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/意外发现谷歌slides的越权漏洞，获得赏金-3133-70的故事</guid>
    <title>意外发现谷歌Slides越权漏洞，获得赏金$3133.70的故事</title>
    <link>https://gugesay.com/blog/意外发现谷歌slides的越权漏洞，获得赏金-3133-70的故事</link>
    undefined
    <pubDate>Mon, 30 Dec 2024 07:07:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Google</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/最新h1越权漏洞披露，获得15000美元奖励</guid>
    <title>最新H1越权漏洞披露，获得15000美元奖励</title>
    <link>https://gugesay.com/blog/最新h1越权漏洞披露，获得15000美元奖励</link>
    undefined
    <pubDate>Mon, 29 Apr 2024 11:25:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>hackerone</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/演绎黑客之术：2000引爆响应操控之力</guid>
    <title>&quot;演绎黑客之术：$2000引爆响应操控之力&quot;</title>
    <link>https://gugesay.com/blog/演绎黑客之术：2000引爆响应操控之力</link>
    undefined
    <pubDate>Wed, 09 Aug 2023 11:18:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/绕过双因素认证至账户接管</guid>
    <title>绕过双因素认证至账户接管</title>
    <link>https://gugesay.com/blog/绕过双因素认证至账户接管</link>
    undefined
    <pubDate>Mon, 22 Jan 2024 08:56:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/致命组合-利用idor实现csrf攻击</guid>
    <title>致命组合--利用IDOR实现CSRF攻击</title>
    <link>https://gugesay.com/blog/致命组合-利用idor实现csrf攻击</link>
    undefined
    <pubDate>Wed, 11 Jan 2023 02:03:26 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>csrf</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/要来点-idor-吗？泄露-6400-万份麦当劳求职申请的漏洞</guid>
    <title>要来点 IDOR 吗？泄露 6400 万份麦当劳求职申请的漏洞</title>
    <link>https://gugesay.com/blog/要来点-idor-吗？泄露-6400-万份麦当劳求职申请的漏洞</link>
    undefined
    <pubDate>Tue, 29 Jul 2025 01:47:16 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>idor</category><category>白帽故事</category><category>麦当劳</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/越权拿下超级管理员权限</guid>
    <title>一个简单的越权漏洞成功拿下Admin权限</title>
    <link>https://gugesay.com/blog/越权拿下超级管理员权限</link>
    undefined
    <pubDate>Tue, 05 Sep 2023 03:17:05 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/重置密码绕过的n种利用姿势</guid>
    <title>重置密码绕过的N种利用姿势</title>
    <link>https://gugesay.com/blog/重置密码绕过的n种利用姿势</link>
    undefined
    <pubDate>Tue, 09 Apr 2024 01:38:05 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

    </channel>
  </rss>
