Scam Alert: streamfluent.ai — The company acknowledged and marked my report as valid. But till now they didn’t provided any response regarding the payout!
Company / Program: streamfluent.ai
Platform: Self-Hosted · Severity: medium · Scam type: no-payout
Published:
Reported by: Abhirup Konwar
Vuln Category: Business Logic Flaw
Description: Destination Free limit of 1 Bypassed
Technique: Race Condition (HTTP/2 Single-Packet Attack)
Asset: www[.]streamfluent[.]ai
Vulnerable endpoint: /api/destinations (POST)
Impact: Leads to unlimited destination if Turbo Intruder used. Since production environment only tested with 4 requests. Similarly applicable to other endpoints with free limits.
Steps to Reproduce
1. Signup for a free account
2. Go to “/dashboard/destinations”
3. Turn on burpsuite proxy, intercept the POST request used to create a destination.
4. Send this request to Burpsuite Repeater tab, make a group of 4 requests , change the body parameters for each request, then finally send the group requests in parallel (HTTP/2 Single-Packet)
5. Refresh your account and verify your bypassed the limit of 1.