infosec

1 article
sort: new top best
clear filter
0 5/10

A researcher discovered an OTP brute-force vulnerability in a login mechanism where missing rate limiting allowed attackers to brute-force 6-digit OTPs by exploiting different response codes for valid/invalid attempts, leading to account takeover. The vulnerability was reported and fixed within a day, earning the researcher a 4-digit bounty payout.

Th3Y0ungM0nk BurpSuite Intruder EditThisCookie
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 17 hours ago · details