Trendyol Live — deeplink proof of concept

Authorized security testing · HackerOne trendyol · researcher x9x
1Open Trendyol Live once
Caches the Trendyol Live scripts. A user who has opened Trendyol Live before is already in this state.
Open Trendyol Live
2Show the session cookies on screen
Attacker JavaScript runs on live.trendyol.com and prints the WebView cookie jar — including token= — into the page.
Show cookies on screen
DDiagnose this device
Prints the raw query string the page received. Screenshot it and count the %25 chain before 2B — that is how many times this device decoded the link, which identifies the correct depth below. Works on any device.
Show what the page received
3Send the session token to this server
Same origin, same sink — this time the token leaves the device as an image request. Watch wrangler tail.

How many times your browser decodes the link before handing it to the app varies by browser, so there is one button per depth. Tap them in order and stop at the first one that works — the log prints which depth succeeded. If a button shows Trendyol's "Beklenmedik bir hata" page, that depth is wrong; just go back and tap the next one.
Send token — depth 1 Send token — depth 2 Send token — depth 3 Send token — depth 4 Send token — depth 5 Send token — depth 6