Posted by adam on Jun 11
I was actually just kidding about releasing it to the list, but given the
nature of the vulnerability – the disclosure could have been a lot worse.
"Is this how it works in all social sites ?"
I've personally witnessed countless sites that authenticate a user based on
userID/token combination (and nothing else). Depending on the actual token
length, bruteforcing it is sometimes even possible.
"If the answer is yes, I will…




