SECURITY PoC — NO AUTH
This movie's CDN stream is playing without login or subscription
Return to Paradise 14 — Episodes (67 of 67)
EP 1Return to Paradise
EP 2Return to Paradise 2
EP 3Return to Paradise 3
EP 4Return to Paradise 4
EP 5Return to Paradise 5
EP 6Return to Paradise 6
EP 7Return to Paradise 7
EP 8Return to Paradise 8
EP 9Return to Paradise 9
EP 10Return to Paradise 10
EP 11Return to Paradise 11
EP 12Return to Paradise 12
EP 13Return to Paradise 13
EP 14Return to Paradise 14
EP 15Return to Paradise 15
EP 16Return to Paradise 16
EP 17Return to Paradise 17
EP 18Return to Paradise 18
EP 19Return to Paradise 19
EP 20Return to Paradise 20
EP 21Return to Paradise 21
EP 22Return to Paradise 22
EP 23Return to Paradise 23
EP 24Return to Paradise 24
EP 25Return to Paradise 25
EP 26Return to Paradise 26
EP 27Return to Paradise 27
EP 28Return to Paradise 28
EP 29Return to Paradise 29
EP 30Return to Paradise 30
EP 31Return to Paradise 31
EP 32Return to Paradise 32
EP 33Return to Paradise 33
EP 34Return to Paradise 34
EP 35Return to Paradise 35
EP 36Return to Paradise 36
EP 37Return to Paradise 37
EP 38Return to Paradise 38
EP 39Return to Paradise 39
EP 40Return to Paradise 40
EP 41Return to Paradise 41
EP 42Return to Paradise 42
EP 43Return to Paradise 43
EP 44Return to Paradise 44
EP 45Return to Paradise 45
EP 46Return to Paradise 46
EP 47Return to Paradise 47
EP 48Return to Paradise 48
EP 49Return to Paradise 49
EP 50Return to Paradise 50
EP 51Return to Paradise 51
EP 52Return to Paradise 52
EP 53Return to Paradise 53
EP 54Return to Paradise 54
EP 55Return to Paradise 55
EP 56Return to Paradise 56
EP 57Return to Paradise 57
EP 58Return to Paradise 58
EP 59Return to Paradise 59
EP 60Return to Paradise 60
EP 61Return to Paradise 61
EP 62Return to Paradise 62
EP 63Return to Paradise 63
EP 64Return to Paradise 64
EP 65Return to Paradise 65
EP 66Return to Paradise 66
EP 67Return to Paradise 67
Per-movie CDN bypass proof
The API returned
playingUrl for Return to Paradise 14
with issubscriber: false, user_access: deny, and paid_for: true.
The video_name + serverhost from the API response are used to construct
the CDN URL above, confirming that the file for this specific movie is
publicly accessible with no authentication.
Security research evidence Inspect entitlement results, CDN URLs, and the raw API response Access control failed
API response evidence
Endpoint called
GET /api/preview/v2/63361/0
User ID used
0 (no user / not logged in)
JWT used
Expired Feb 2024 (extracted from APK)
issubscriber
false
user_access
paid_for
YES (premium content)
substatus
EXPIRED
serverhost
47
video_name
14.Return to Paradise.-..VJ.Ashim.mp4
playingUrl returned
YES — URL in response
API playingUrl value
https://munowatch.co/clips/ELI.mp4
CDN stream
https://munotek-vault.b-cdn.net/stw42/fya/14.Return%20to%20Paradise.-..VJ.Ashim.mp4
Finding: The server sets user_access=deny and
issubscriber=false but still returns playingUrl in the
same response. Subscription is enforced client-side only — any caller with
the expired APK JWT can obtain stream URLs without a subscription.
Munowatch CDN (b-cdn.net) serves content with no auth required
(direct HTTP Range requests succeed with HTTP 206).