multi-factor-authentication

1 article
sort: new top best
clear filter
0 8/10

A logic flaw in 2FA implementation across multiple platforms (Google, Microsoft, Instagram, Cloudflare) allows an attacker to maintain persistence after password recovery by exploiting session renewal in the 2FA page and leveraging the fact that disabled 2FA codes still validate, enabling account takeover without knowing the current password.

Google Microsoft Instagram Facebook Cloudflare Algolia GitHub LinkedIn Luke Berner HackerOne Bugcrowd
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details