Back to directory
WRITEUP #3980

Is Math.random() Safe? from missing rate limit to bypass 2fa and possible sqli

Race ConditionLack of rate limitingOTP bypassSQL injection
by@boomneroli(Yasser Mohammed)
Program
-
Published
Feb 20, 2021
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://neroli.medium.com/is-math-random-safe-from-missing-rate-limit-to-bypass-2fa-and-possible-sqli-2a4ea66f82c5
RELATED WRITEUPS
Directory Traversal, SQL Injection and Server-Side Request Forgery
SQL InjectionPath traversal
Breaking Down Barriers: Exploiting Pre-Auth SQL Injection In WhatsUp Gold - CVE-2024-6670
SQL InjectionReverse engineering
Bypassing airport security via SQL injection
SQL Injection
World of SELECT-only PostgreSQL Injections: (Ab)using the filesystem
SQL Injection
ArtiPACKED: Hacking Giants Through a Race Condition in GitHub Actions Artifacts
Race ConditionCI/CD

Built with ❤️ by Shubham Rawat