token-reuse

2 articles
sort: new top best
clear filter
0 5/10

A 2FA bypass vulnerability was discovered on Pandao.ru (Mail.ru's extended program) where CSRF tokens used to disable 2FA never expire, allowing an attacker to reuse the same token to disable 2FA on victim accounts. The vulnerability was reported but no bounty was awarded as the program excludes client-side attacks.

Mail.ru Pandao.ru HackerOne BurpSuite Vishal Bharad
vbharad.medium.com · kh4sh3i/bug-bounty-writeups · 22 hours ago · details
0 6/10

Educational writeup demonstrating multiple 2FA bypass techniques including SMS OTP redirection via parameter manipulation, token reuse attacks, lack of rate limiting on OTP verification, and expired confirmation token exploitation. Includes case studies from HackerOne and bug bounty programs.

Gaurav Narwani HackerOne Google Facebook Skype Grab login.gov
gauravnarwani.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details