TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Using Lyft share link you can pull all names of users

5 点作者 mauerbac超过 11 年前
It seems through Lyft's new share link you can pull the names of all the users. Ex: https://www.lyft.com/invited/MATT2398. Decrementing the last four digits exposes other users. You can try this with other names. Not sure if this is a vulnerability since it's just names. Surprised they didn't hash them.

1 comment

steveklabnik超过 11 年前
You should probably report this to Lyft directly.