Trendyol Live — deeplink proof of concept
Authorized security testing · HackerOne trendyol · researcher x9x
1Open Trendyol Live once
Caches the Trendyol Live scripts. A user who has opened Trendyol Live
before is already in this state.
Open Trendyol Live
2Show the session cookies on screen
Attacker JavaScript runs on live.trendyol.com and prints the
WebView cookie jar — including token= — into the page.
Show cookies on screen
DDiagnose this device
Prints the raw query string the page received. Screenshot it and count
the %25 chain before 2B — that is how many times this device
decoded the link, which identifies the correct depth below. Works on any device.
Show what the page received
3Send the session token to this server
Same origin, same sink — this time the token leaves the device as an
image request. Watch wrangler tail.
How many times your browser decodes the link before handing it to the app
varies by browser, so there is one button per depth. Tap them in order and stop at
the first one that works — the log prints which depth succeeded. If a button shows
Trendyol's "Beklenmedik bir hata" page, that depth is wrong; just go back and tap the
next one.
Send token — depth 1
Send token — depth 2
Send token — depth 3
Send token — depth 4
Send token — depth 5
Send token — depth 6