SECURITY PoC — NO AUTH
CDN bypass demo: stream served without an auth header
Dong Yi 9 — Episodes (60 of 60)
EP 1Dong Yi
EP 2Dong Yi 2
EP 3Dong Yi 3
EP 4Dong Yi 4
EP 5Dong Yi 5
EP 6Dong Yi 6
EP 7Dong Yi 7
EP 8Dong Yi 8
EP 9Dong Yi 9
EP 10Dong Yi 10
EP 11Dong Yi 11
EP 12Dong Yi 12
EP 13Dong Yi 13
EP 14Dong Yi 14
EP 15Dong Yi 15
EP 16Dong Yi 16
EP 17Dong Yi 17
EP 18Dong Yi 18
EP 19Dong Yi 19
EP 20Dong Yi 20
EP 21Dong Yi 21
EP 22Dong Yi 22
EP 23Dong Yi 23
EP 24Dong Yi 24
EP 25Dong Yi 25
EP 26Dong Yi 26
EP 27Dong Yi 27
EP 28Dong Yi 28
EP 29Dong Yi 29
EP 30Dong Yi 30
EP 31Dong Yi 31
EP 32Dong Yi 32
EP 33Dong Yi 33
EP 34Dong Yi 34
EP 35Dong Yi 35
EP 36Dong Yi 36
EP 37Dong Yi 37
EP 38Dong Yi 38
EP 39Dong Yi 39
EP 40Dong Yi 40
EP 41Dong Yi 41
EP 42Dong Yi 42
EP 43Dong Yi 43
EP 44Dong Yi 44
EP 45Dong Yi 45
EP 46Dong Yi 46
EP 47Dong Yi 47
EP 48Dong Yi 48
EP 49Dong Yi 49
EP 50Dong Yi 50
EP 51Dong Yi 51
EP 52Dong Yi 52
EP 53Dong Yi 53
EP 54Dong Yi 54
EP 55Dong Yi 55
EP 56Dong Yi 56
EP 57Dong Yi 57
EP 58Dong Yi 58
EP 59Dong Yi 59
EP 60Dong Yi 60
CDN bypass demonstration
The API returned
playingUrl for Dong Yi 9
with issubscriber: false and user_access: deny.
The video above plays from Munowatch's own CDN with
zero authentication.
Security research evidence Inspect entitlement results, CDN URLs, and the raw API response Access control failed
API response evidence
Endpoint called
GET /api/preview/v2/43093/0
User ID used
0 (no user / not logged in)
JWT used
Expired Feb 2024 (extracted from APK)
issubscriber
false
user_access
deny
paid_for
YES (premium content)
substatus
EXPIRED
serverhost
58
video_name
Dong Yi Episode 9.mp4
playingUrl returned
YES — URL in response
API playingUrl value
https://munowatch.co/clips/ELI.mp4
CDN demo stream
https://nkuba.b-cdn.net/cleve48/cfr/In.The.Grey.mp4
Finding: The server sets user_access=deny and
issubscriber=false but still returns playingUrl in the
same response. Subscription is enforced client-side only — any caller with
the expired APK JWT can obtain stream URLs without a subscription.
Munowatch CDN (b-cdn.net) serves content with no auth required
(direct HTTP Range requests succeed with HTTP 206).