2fa-bypass

8 articles
Sort: New Top Best
clear filter
0
infosecwriteups.com · kh4sh3i/bug-bounty-writeups · 4 hours ago · details
0 5/10

Researcher bypassed 2FA on a private program by discovering that the 2FA verification endpoint did not validate the Google Captcha header (unlike the login endpoint), allowing brute-force of TOTP codes within the 59-second window using 888 threads in Burp Intruder.

Google Authenticator Burp Pro Turbo Intruder
shivangx01b.github.io · kh4sh3i/bug-bounty-writeups · 4 hours ago · details
0

A vulnerability in Instagram's account reactivation process allowed attackers to reactivate deactivated accounts using only credentials, bypassing two-factor authentication that should have been required. The issue was fixed by Instagram after being reported through their bug bounty program, resulting in a $500 bounty award.

Instagram Facebook Aman Shahid HackerOne
bugbountypoc.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details