Writeups
-
Easy
2FA bypass using a brute force attack
2fa bypass by brute forcing the four digit code
Authentication 3 min -
Easy
broken brute force protection, multiple credentials per request
broken brute force protection that counts login requests rather than guesses, defeated by submitting the entire password list as a JSON array in one request so every candidate is tested against carlos at once
Authentication 2 min -
Easy
Password brute-force via password change
password brute force through the change password form, where sending mismatched new passwords avoids the account lock and makes the error message leak when a guessed current password is correct
Authentication 3 min -
Easy
password reset poisoning via middleware
password reset poisoning where the reset link host is built from the X-Forwarded-Host header
Authentication 3 min -
Easy
Offline password cracking
offline password cracking where a stay logged in cookie holds an MD5 password hash, stolen through stored XSS
Authentication 3 min -
Easy
Brute-forcing a stay-logged-in cookie
brute forcing a stay logged in cookie that is just base64(username + ':' + md5(password))
Authentication 3 min -
Easy
2FA broken logic
broken 2fa logic where the second stage trusts a client supplied verify parameter to choose the account, abused to generate a victim code then brute force the four digit value and land in their session
Authentication 1 min
Nothing matched that.
No writeups here yet. Try a broader tag, or clear the filter to see everything.
Clear filters