The First Reference Principle: Finding Weak Trust Inputs
Farzan introduced the ABSAC principle: identifying the first point where a sensitive value is introduced upstream in a web app. Trust assumptions are strongest there but authentication weakest. He gave an example: a search API returns metadata like actor IDs. Those IDs can feed another API to get more data, eventually leading to a video stream URL, all unauthenticated. This chain of interdependent API calls is what RRE exploits recursively.
Manual RRE Walkthrough on a Sports Streaming Service
Karimi demonstrated RRE manually. He searched for a football game while logged out. The video didn’t play. After logging in, Burp Suite captured the API response containing a video stream URL. He replayed that stream in VLC successfully, bypassing the web app. Then he traced the stream parameter backwards: the VOD parameter came from a GAM ID, which came from an unauthenticated search. The chain starts from public metadata.
Automating with Recursive Entropy Checks
The challenge: manual RRE doesn’t scale. Karimi solved this by implementing Shannon entropy checks to identify which parameters in API responses are likely to be secrets and which are public identifiers. Version 2 of his Burp extension recursively traces the entire chain automatically. A 140-second demo showed the tool generate the full API chain for a baseball game stream in seconds, work that could take a pentester hours or days.
Real-World Results and Privacy Implications
Using the recursive trace, Karimi pulled every live stream and highlight from the sports streaming service in a single day. He discovered always-on cameras streaming empty arenas, a privacy nightmare. The same RRE technique uncovered an IDOR bug in another streaming service: by stripping API calls to a single numeric ID, he enumerated over 1,800 internal company all-hands meetings. The API leaked event metadata and even provided the OAuth token needed to view videos.
Notable Quotes
uh one I was able to leverage this technique to target a sports streaming service to get all their content for free Farzan Karimi · ▶ 1:22
I also was able to target another major streaming service uh to access over 1,800 internal company meetings uh videos for internal company all hands global town halls etc. Farzan Karimi · ▶ 1:30
So we’re just attacking metadata here if that makes sense. Farzan Karimi · ▶ 12:32
it’s a cherry on top finding. Farzan Karimi · ▶ 16:00
this a big privacy nightmare, right? Farzan Karimi · ▶ 16:29
Key Takeaways
- RRE automates tracing interdependent web APIs in reverse to find unauthenticated access.
- Entropy-based recursion turns hours of manual pentesting into seconds.
- Always-on live streams and IDOR bugs in streaming services pose serious privacy risks.
About the Speaker(s)
Farzan Karimi has 20 years experience in offensive security. He is currently the Senior Director of Attack Operations at Moderna. Formerly, he managed the Android Red Team at Google and the red team at Electronic Arts. Farzan has been interviewed by Wired Magazine and was featured on Ted Danson’s Advancements. He is an avid speaker at security conferences such as DEFCON and Black Hat USA, where he presented on the topics of Pixel exploitation and cellular security.