rate-limit

1 article
sort: new top best
clear filter
0 7/10

Researcher demonstrates chaining missing rate limits with Math.random() predictability via race conditions to bypass 2FA OTP validation in a Node.js-based React-Native mobile application, combined with SQL injection in the OTP endpoint affecting multiple authentication flows.

Yasser Mohammed HackerOne React-Native Math.random() Turbo Intruder Burp Suite OWASP
neroli.medium.com · kh4sh3i/bug-bounty-writeups · 22 hours ago · details