2FA simple bypass
https://portswigger.net/web-security/authentication/multi-factor/lab-2fa-simple-bypass
Level: Apprentice
data:image/s3,"s3://crabby-images/3430f/3430f8d2e8a0898d9cff25f6966a7219319104a8" alt=""
This is just a simple 2FA Bypass, that it.
First, start authenticating to see what we can do with it.
data:image/s3,"s3://crabby-images/90945/90945439e078b71fd1d92945e8ac1b3a10e2dfd2" alt=""
Okay once we put the password and username, it tells us that an email has been sent to the respective user email.
data:image/s3,"s3://crabby-images/24e7f/24e7f20b1ab9ac3923cd6556d9e33d9a1f390543" alt=""
Just to see what I can modify I put the 4-digit pin into it.
Nothing interesting for now.
data:image/s3,"s3://crabby-images/08547/08547bb8039ca9d9a0db4752320b4b02ebdce663" alt=""
Knowing that is a simple 2FA Bypass, I've seen that once you log in with the user credentials there is a
/login2
So, try to change it to
/my-account
or/login1
to see what can happen.
data:image/s3,"s3://crabby-images/1d57f/1d57f2617923ee75d1a993b7e947f6837decfe61" alt=""
Just getting out the
/login2
you get into the user account, that's how simple it is.
data:image/s3,"s3://crabby-images/fe171/fe17103c09a87850bfb42ce77cd4c8f44e75c853" alt=""
Last updated