techlore / go-incognito

Go Incognito: A Guide to Security, Privacy, & Anonymity
340 stars 13 forks source link

Courses are easily enumerated #29

Open jonaharagon opened 1 month ago

jonaharagon commented 1 month ago

(reported by forum beta tester)

In a similar vein, the url for the Go Incognito v1 course is view.php?id=2, incrementing by ones, you’re able to see that there are hidden courses at id=3 and id=4, which give an error that displays “This course is unavailable to students.”, which differs from other ids, which return “Can’t find data record in database table course.