DuckDuckGo disclosed on HackerOne
In Summary : Normally, a call to ` https://duckduckgo.com/iu` contains a query parameter (`u`) with some path using the domain ` yimg.com ...
https://updatesinfosec.blogspot.com/2018/08/duckduckgo-disclosed-on-hackerone.html
Normally, a call to `https://duckduckgo.com/iu` contains a query parameter (`u`) with some path using the domain `yimg.com`. This call will succeed in[...]
kindly refer the following link as follow up :
https://hackerone.com/reports/398641