MikeChan
1 min readJul 12, 2020

--

One thing not really understand. If they only check last requested id without checking if it is belong to same user session. How was the back end server know it was sent by the user?

--

--

MikeChan
MikeChan

Written by MikeChan

Cybersecurity, Part-time bug bounty hunter. Support me by subscribe: https://mikekitckchan.medium.com/membership. Ping me for online private tutoring.

Responses (1)