Settings

Theme

Leaked Secrets and Unlimited Miles: Hacking the Largest Rewards Vendor

samcurry.net

5 points by rez0__ 2 years ago · 1 comment

Reader

rez0__OP 2 years ago

"On May 2nd, 2023, we identified that the Flask session secret for the points[.]com global administration website used to manage all airline tenant and customer accounts was the word 'secret'."

And so many insane vulnerabilities found and exposed by these guys. Hats off!

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection