multi-factor-authentication-bypass

1 article
sort: new top best
clear filter
0 6/10

Security researcher Laxman Muthiyah discovered a critical account takeover vulnerability in Microsoft's password reset mechanism that allowed brute-forcing 7-digit security codes by sending concurrent requests to bypass rate limiting and IP-based blacklisting. The vulnerability affected both standard accounts and those with 2FA enabled, requiring approximately 11 million concurrent requests to compromise any Microsoft account.

Laxman Muthiyah Microsoft MSRC HackerOne Instagram iCloud
thezerohack.com · kh4sh3i/bug-bounty-writeups · 19 minutes ago · details