Resources

People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!

Bypassing Hotstar Premium with Dom Manipulation - 96

opsecxPosted 6 Years Ago
  • Although using security controls on the client-side is a really bad idea, reversing minified JavaScript is not fun at all! I thought this was a really funny comment :)
  • The application had an overlay, over the main content. After erasing this DOM element and changing another element from hide to shoe the movie content started to display!
  • At this point though, the content would play for a second then stop playing.
  • In order to complete this exploit, a piece of JavaScript was added to the console to just 'click' the play button continually!
  • This vulnerability was hilarious and had a funny ending! :)