May 10, 2024, 4:55 a.m. | Ronak Patel

InfoSec Write-ups - Medium infosecwriteups.com

Hi Fellow Hackers!!!

Happy New Year!!!

This Write-Up is about the same program i mentioned in my another article “https://medium.com/@ronak-9889/admin-account-takeover-ab7535fe0fdb

As mentioned in that write-up this program introduced new feature called “Custom role” which allows admin to create user with custom permissions. One of the permission which could be assigned was “Access to security section”

As seen above Imagine Admin has created user with the custom role which has only “access to security section” admin permission.

As seen …

access control bug bounty cybersecurity information security privilege escalation

Sr. Product Manager

@ MixMode | Remote, US

Assoc/Mid ET P&C Control System Field Compliance Analyst (Glen Allen, VA)

@ Dominion Energy | GLEN ALLEN, VA, US, 23060

Technology Risk & Controls Lead- PCI Compliance

@ JPMorgan Chase & Co. | Plano, TX, United States

Editor, Compliance Risk and Diligence

@ Kroll | Manila, Philippines

KGS - KDN IAM Associate Consultant - Bengaluru

@ KPMG India | Bengaluru, Karnataka, India

KGS - IAM KDN Consultant - Bengaluru

@ KPMG India | Bengaluru, Karnataka, India