F. Maury ⏚<p>D'après la documentation de One Drive, c'est parfaitement OK de faire fuiter des miniatures d'images privées par des URL publiques sans contrôle d'accès :</p><p><a href="https://learn.microsoft.com/fr-fr/onedrive/developer/rest-api/api/driveitem_list_thumbnails?view=odsp-graph-online#retrieve-thumbnail-binary-content" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">learn.microsoft.com/fr-fr/oned</span><span class="invisible">rive/developer/rest-api/api/driveitem_list_thumbnails?view=odsp-graph-online#retrieve-thumbnail-binary-content</span></a></p><p>> Les URL des miniatures sont des URL de cache sécurisées.</p><p>J'y penserai s'il me vient à l'idée de stocker des dick pics sur One Drive 👀 </p><p><a href="https://infosec.exchange/tags/onedrive" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>onedrive</span></a> <a href="https://infosec.exchange/tags/fuckoff" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fuckoff</span></a> <a href="https://infosec.exchange/tags/onedrive" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>onedrive</span></a> <a href="https://infosec.exchange/tags/cloud" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cloud</span></a> <a href="https://infosec.exchange/tags/storage" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>storage</span></a></p>