Web Hack List

Collected research

How I Accessed 1,800 Company Livestreams and Uncovered a New Web Exploit Class: RRE

Recursive Request Exploits trace a chain of dependent API calls backwards from a sensitive value such as a stream identifier to the first request that introduces it, then abuse the earliest hop that enforces no authentication. The method reached 1,800 private corporate livestreams without logging in; a proxy extension ranks candidate tokens by entropy to automate the trace.

Record

Researcher
Farzan Karimi
Published by
Medium
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Farzan Karimi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .