playingUrl for Conquer: Lahad Datu
with issubscriber: false, user_access: deny, and paid_for: true.video_name + serverhost from the API response are used to construct
the CDN URL above — confirming that the CDN file for this specific movie is
publicly accessible with no authentication.
The Malaysian security forces in quelling the militant group of the Sulu Sultanate aka "Operation Daulat" in Lahad Datu, Sabah
Finding: The server sets user_access=deny and
issubscriber=false but still returns playingUrl in the
same response. Subscription is enforced client-side only — any caller with
the expired APK JWT can obtain stream URLs without a subscription.
Munowatch CDN (b-cdn.net) serves content with no auth required
(direct HTTP Range requests succeed with HTTP 206).
{
"id": 55334,
"video_title": "Conquer: Lahad Datu",
"description": "The Malaysian security forces in quelling the militant group of the Sulu Sultanate aka \"Operation Daulat\" in Lahad Datu, Sabah",
"video_name": "Conquer Lahad Datu VJ ICE P.mp4",
"filehistory": "",
"openload": "0",
"embedurl": "",
"serverhost": "60",
"allow_openload": "0",
"full_video_name": "",
"duration": "01h 59m",
"thumbnail": "https://apposters.b-cdn.net/laba/yo/naki/EP9MJbHNE17265.jpg",
"tfilehistory": "",
"category_id": 1,
"language_id": 1,
"recording_date": "2025-03-11",
"age_id": "18 +",
"location": 1,
"tab_category_id": 1,
"series_code": "55334",
"access": "1",
"paid_for": "1",
"new_movie": "1",
"priority": "No",
"size": "975.04 MB",
"create_date": "2025-03-11 02:03:38",
"schedule_date": "11.03.2025 09:41:42 AM",
"user_id": 1118356,
"vj_id": 9,
"video_status_id": 0,
"network_id": "45.221.10.185",
"user_access": "deny",
"notification": "No",
"secduration": "7160.000000",
"issubscriber": false,
"genre": "Action",
"vjname": "Vj Ice P",
"trailer_playing_url": "",
"episodes": 0,
"episode_state": "",
"nxt_eps": "",
"nxt_eps_id": 0,
"nxt_eps_title": "",
"nxt_ldur": 0,
"nxt_playing_url": "https://munowatch.co/clips/ELI.mp4",
"playingUrl": "https://munowatch.co/clips/ELI.mp4",
"ldur": 2742,
"session_id": "cb99afb5b31411a57538a97393de0e2e",
"device": "web",
"lang_name": "English to Luganda",
"vjrelease": "1 year ago",
"mstatus": false,
"kstatus": "",
"substatus": "EXPIRED"
}