google-authenticator

1 article
Sort: New Top Best
clear filter
0 5/10

Researcher bypassed 2FA on a private program by discovering that the 2FA verification endpoint did not validate the Google Captcha header (unlike the login endpoint), allowing brute-force of TOTP codes within the 59-second window using 888 threads in Burp Intruder.

Google Authenticator Burp Pro Turbo Intruder
shivangx01b.github.io · kh4sh3i/bug-bounty-writeups · 5 hours ago · details