Content pfp
Content
@
0 reply
0 recast
0 reaction

Hyperfatfingger pfp
Hyperfatfingger
@heapoverflow.eth
@nook @slokh @emo.eth nook.social has an interesting logical redirection bug, which doesn't impact normal website usage, hence the decision to disclose it. The bug is triggered when visiting a user's homepage (e.g., users/1), where '1' is the fid (user ID).
5 replies
0 recast
4 reactions

Hyperfatfingger pfp
Hyperfatfingger
@heapoverflow.eth
Nook doesn't distinguish between username and fid, leading to incorrect redirection when a username identical to a fid is used. As an example, @jessepollak 's fid is '99', if we attempt to visit a user with the username '99', we are wrongly redirected to 'jesse's' homepage.
0 reply
0 recast
0 reaction