Back to directory
WRITEUP #2301

ASP.NET Boilerplate Multiple Vulnerabilities

Auth BypassBroken authenticationHardcoded credentialsJWTPadding oracle attackCryptographic issues
by@bigshika(Sana Oshika)
Program
Volosoft (ASP.NET Boilerplate)
Published
Aug 26, 2022
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://pulsesecurity.co.nz/advisories/aspnetboilerplate-jwt
RELATED WRITEUPS
Plug Security Holes in React Apps That Can Lead to API Exploitation
Auth BypassSSO
Account Takeover via Broken Authentication Workflow: Free Lifetime Streaming!
Auth BypassBroken authentication
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
Instagram and Meta 2FA Bypass by Unprotected Backup Code Retrieval in Accounts Center
Auth Bypass2FA / MFA bypass
Forced SSO Session Fixation
Auth BypassSSO

Built with ❤️ by Shubham Rawat