backup-codes

1 article
sort: new top best
clear filter
0 6/10

A researcher discovered a 2FA bypass vulnerability where backup codes were not validated, allowing any random 8-digit number to successfully authenticate instead of the legitimate backup code. The vulnerability was due to missing input validation on the backup code authentication path.

Google Authenticator ultranoob
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details