2factor auth bypass

  Рет қаралды 9,096

Bug Bounty poc

Bug Bounty poc

Жыл бұрын

An attacker can perform an Authentication bypass...
check it before comment this not a bug
Note: Hi there,
Thanks for the report. What you are showing is that the authentication cookies are not being expired on logout. This issue is considered out-of-scope as documented in our vulnerability disclosure policy as it is classified as a low severity vulnerability (P4 or P5) according to Bugcrowd’s Vulnerability Rating Taxonomy. As stated in our policy, we do not pay bounties for such issues.
Best,

Пікірлер: 26
@steiner254
@steiner254 Жыл бұрын
That's not a bug. You've copied even the userID.. That's a p5. Unless you demostrate where the application leaks respective user ID's.
@ravichander941
@ravichander941 Жыл бұрын
Also the userid is encrypted so we can't even brute force it
@steiner254
@steiner254 Жыл бұрын
@@ravichander941 mehn...
@naumanbackupstests746
@naumanbackupstests746 Жыл бұрын
He even paste the cookies that never expired
@steiner254
@steiner254 Жыл бұрын
@@naumanbackupstests746 😅aiseee
@bugbountypoc4096
@bugbountypoc4096 Жыл бұрын
I really agree with all of you and after the report I also thought about it but it was accepted as a p4. the company also told me in this same topic.. so, they considered as a session not expire...
@hossamshady1383
@hossamshady1383 8 ай бұрын
the question as triager where did you got the cookies of response , there is set-cookie response that can't be bypass 2fa and if so it would be p4 or p5
@bugbountypoc4096
@bugbountypoc4096 8 ай бұрын
Bro please check the description box. I have already mentioned
@hiddenstar3393
@hiddenstar3393 Жыл бұрын
Was that a 2fa bypass through a response manipulation ?
@bugbountypoc4096
@bugbountypoc4096 Жыл бұрын
yes
@edavidwaner2187
@edavidwaner2187 4 ай бұрын
intresting ✌✌✌✌
@itsm3dud39
@itsm3dud39 Жыл бұрын
on which platform you find this program?
@bugbountypoc4096
@bugbountypoc4096 Жыл бұрын
www.nuclino.com/vulnerability-disclosure-policy
@Xpl0itme921
@Xpl0itme921 Ай бұрын
This is not a bug nor 2fa bypass you just copy the cookies and paste it on the response.
@bugbountypoc4096
@bugbountypoc4096 Ай бұрын
I agree. But session cookie must be expire after log out.
@Xpl0itme921
@Xpl0itme921 Ай бұрын
@@bugbountypoc4096 please change the title it help to understand the poc for all
@c09yc47
@c09yc47 Жыл бұрын
This is not a bug bro
@bugbountypoc4096
@bugbountypoc4096 Жыл бұрын
2fa bypass using old session. That is also a part of a 2fa bypass. this report was considered as p4.
@satishpyata1795
@satishpyata1795 Жыл бұрын
That's not a bug.
@bugbountypoc4096
@bugbountypoc4096 Жыл бұрын
2fa bypass using old session. That is also a part of a 2fa bypass. check it on google
@tsumogi
@tsumogi Жыл бұрын
@@bugbountypoc4096 but that means the attacker would already have to have access to the account, making the 2fa bypass useless since the attacker is already in the account
@zzzzzzzzZzZZzzzaZzz
@zzzzzzzzZzZZzzzaZzz Жыл бұрын
where the bypass ?
@bugbountypoc4096
@bugbountypoc4096 11 ай бұрын
2fa bypass using the old cookie. why does this not bypass????
@zzzzzzzzZzZZzzzaZzz
@zzzzzzzzZzZZzzzaZzz 11 ай бұрын
@@bugbountypoc4096 Nice and how you got the old cookie ?
Authentication OTP bypass | POC Bug Hunting | Lazy Pentester
1:29
Lazy Pentester
Рет қаралды 9 М.
OTP Bypass Using Burp Suite
1:15
All about Hacking
Рет қаралды 31 М.
World’s Deadliest Obstacle Course!
28:25
MrBeast
Рет қаралды 86 МЛН
Купили айфон для собачки #shorts #iribaby
00:31
A pack of chips with a surprise 🤣😍❤️ #demariki
00:14
Demariki
Рет қаралды 41 МЛН
How hackers Bypass Multi Factor Authentication | Evilginx 2
8:14
Cyberlinx Security
Рет қаралды 73 М.
How Hackers Bypass Two-Factor Authentication (2FA)?!
9:20
Loi Liang Yang
Рет қаралды 106 М.
Reflected XSS on hidden parameter
1:49
Bug Bounty poc
Рет қаралды 3,5 М.
Купил этот ваш VR.
37:21
Ремонтяш
Рет қаралды 262 М.
iPhone 12 socket cleaning #fixit
0:30
Tamar DB (mt)
Рет қаралды 43 МЛН
Ждёшь обновление IOS 18? #ios #ios18 #айоэс #apple #iphone #айфон
0:57
WWDC 2024 - June 10 | Apple
1:43:37
Apple
Рет қаралды 10 МЛН