response-length-analysis

1 article
sort: new top best
clear filter
0 5/10

A brute-force attack vulnerability was discovered in Oculus identity verification during username changes, where the lack of rate limiting allowed an attacker to enumerate 6-digit OTP codes and distinguish valid codes from invalid ones by analyzing response length differences (840 bytes for valid, 1152 for invalid).

Oculus Facebook Karthik Kumar Reddy Gmail Burp Suite
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details