Eight Access Control Flaws in Feeld’s APIs
Feeld, a dating app with over 1 million Android downloads, launched in 2014 as Trender. Bogdan Tiron discovered eight access control vulnerabilities in its GraphQL and REST APIs. The first: disclosure of profile information to non-premium users. A basic user sees only blurred photos in the “Who Liked You” menu. Intercepting the GraphQL response with Burp reveals full photos and the stream user ID. This ID enables further attacks.
Reading Messages and Leaking Attachments
Using the stream user ID from the first vulnerability, an attacker can read any user’s messages. The endpoint /channels accepts a members parameter with the victim’s stream user ID. The response contains all sent and received messages. In one test, 92 matches appeared for a victim. Messages include attachments: photos and videos. The app offers replayable and time-limited media. The backend fails to verify sender or receiver identity, allowing unauthorized access.
Photos and Videos Public Without Authentication
Replayable photos are uploaded to Cloudinary and served from two endpoints: sender and receiver. The backend does not check which user is requesting. An attacker can use any letter in place of the sender or receiver ID and still retrieve the photo. Time-limited photos require the sender’s profile ID. Videos are simpler: the URL contains a placeholder that must be swapped for an ampersand. All media is accessible without authentication via a v1 endpoint.
Delete, Recover, Edit Messages and Update Profiles
Vulnerability four: delete, recover, and edit other people’s messages. The endpoint /messages/{messageId} accepts DELETE and PUT methods without authorization. Deleting a message twice recovers the original content. Editing a message changes its text, and the victim sees “edited” but not who edited. Vulnerability five: update someone else’s profile. The GraphQL operation profileUpdate accepts a profile ID parameter. Swapping the ID updates another user’s biography, name, or age.
Send Likes, Messages, and View Matches as Other Users
Vulnerability six: send a like from any profile. Logged in as user A, an attacker can send a like from user B to user C. The backend only prevents liking your own profile. Vulnerability seven: send messages in other people’s chats. Using a channel ID from the victim’s messages, an attacker can post a message. Because usernames are not unique, impersonation is possible. Vulnerability eight: view other people’s matches. The chatListQuery operation returns matches for any profile ID supplied.
Q&A
How can automated tools detect IDOR vulnerabilities like swapping profile IDs? It is difficult because the response looks valid; intuition is required, and no current tool can compare responses to detect unauthorized access. ▶ 24:25
Notable Quotes
all the videos are public online unauthenticated Bogdan Tiron · ▶ 15:09
you can even impersonate one of the uh counterparts in the chat Bogdan Tiron · ▶ 21:35
the back end doesn’t even check the sender grid or the receiver grid Bogdan Tiron · ▶ 8:03
Key Takeaways
- Eight access control vulnerabilities were found in Feeld’s GraphQL and REST APIs, affecting over 1 million users.
- All photos and videos were accessible without authentication due to missing authorization checks.
- The issues were fixed after six months; the research is published on FORTBRIDGE’s blog.
About the Speaker(s)
Bogdan Tiron is a seasoned security consultant with over 10 years of experience specializing in application security. He has a proven track record of enhancing security measures for leading organizations, including bet365, JPMorgan Bank, GFK, HSBC, Lloyds Bank, and WorldRemit. Throughout his career, Bogdan has held various roles, including application security consultant, pentester, security architect, and DevSecOps specialist. Four years ago, recognizing a gap in quality within the pentesting industry, he co-founded FORTBRIDGE, a cybersecurity consulting company that offers pentesting, phishing, and red-teaming services to clients seeking to enhance their security posture. Passionate about staying ahead of emerging threats, Bogdan is dedicated to fostering a culture of security within organizations and empowering teams to integrate security practices seamlessly into their workflows.