Mickaël Walter
Sign in

web

A collection of 2 posts
IDOR with MongoDB: understanding ObjectID
web

IDOR with MongoDB: understanding ObjectID

Given their complex appearance, some would think that exploiting IDOR based on MongoDB's ObjectID would be difficult. This is not the case as the ObjectID is not random
14 Nov 2018 3 min read
Account enumeration on web applications
web

Account enumeration on web applications

Why a generic message to prevent user enumeration is an acceptable user experience degradation to improve security
26 Dec 2017 2 min read
Page 1 of 1
Mickaël Walter © 2025
  • twitter
  • github
  • linkedin
  • mastodon
Powered by Ghost