two-factor-authentication-bypass

2 articles
sort: new top best
clear filter
0 4/10

Researcher bypassed two-factor authentication by removing the VerificationDetails JSON parameter from a settings API endpoint, allowing 2FA to be toggled on/off without providing a valid OTP code. The vulnerability exploited insufficient server-side validation of required fields.

Aung Pyae Ko Ko
aungpyaekoko.medium.com · kh4sh3i/bug-bounty-writeups · 20 hours ago · details
0 6/10

Educational writeup demonstrating multiple 2FA bypass techniques including SMS OTP redirection via parameter manipulation, token reuse attacks, lack of rate limiting on OTP verification, and expired confirmation token exploitation. Includes case studies from HackerOne and bug bounty programs.

Gaurav Narwani HackerOne Google Facebook Skype Grab login.gov
gauravnarwani.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details