How to get URL link on X (Twitter) App
*HTTP
* Predictable/flawed password reset token
Banking apps often have extra security measures in place and sometimes those security measures backfire. In this scenario, the app had implemented a re-auth mechanism after the app was closed. However, for whatever reason, the session was still alive in the background.
1. Application-level ID Leakage
* Check all schemes (http, https, file, ftp, gopher, etc)