Fonctionnement
Périmètre autorisé, puis boucle de test.
Six étapes. Pas de complétude implicite.
Nubesti LLC Delaware, United States
-
01
Définir le périmètre
Actifs et autorisation. KYC payé.
-
02
Reconnaissance
Surface autorisée uniquement.
-
03
Simulation et validation
Chemins exploitables dans ce périmètre.
-
04
Preuve
Contexte technique recevable ou rejetable.
-
05
Remédiation
Recommandations ou brouillons de correctifs.
-
06
Retest
Nouveau passage après correction.
Avant un test
KYC et autorisation.
Nubesti Security Lab
Un constat — clairement de laboratoire.
Enregistrement de laboratoire. Pas un client, pas un hôte de production.
- Asset
- api.lab.nubesti.test
- Finding
- Broken object-level authorization
- Severity
- Critical
- MITRE ATT&CK
- T1190 — Exploit Public-Facing Application
- Evidence
- Request / Response pair from a controlled replay against the lab API
- Exploitability
- Validated in the lab (object ID swapped; another tenant record returned)
- Impact
- Unauthorized read of another account’s records in the lab dataset
- Remediation
- Enforce object-level authorization on every record access; add regression tests
- Status
- Fixed in lab build 2026.09
- Retest
- Passed