Walkthroughs of Uphack labs: the product the bug lives in, the request that proves it, and the check that closes it.
How different password and SSO confirmation paths expose an IDOR in an investment account closure endpoint, including the request comparison, vulnerable code, impact, and ownership fix.
How a nested digest[email] parameter becomes autofocus and onfocus attributes in a newsletter signup, including the payload, vulnerable code and fix.
How a Base64-encoded return reference leads to IDOR in a financial action: the request, decoded JSON, modified payload, vulnerable code, impact, and correct ownership check.