WRITEUP #3980
Is Math.random() Safe? from missing rate limit to bypass 2fa and possible sqli
Race ConditionLack of rate limitingOTP bypassSQL injection
by@boomneroli(Yasser Mohammed)
Program
-
Published
Feb 20, 2021
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://neroli.medium.com/is-math-random-safe-from-missing-rate-limit-to-bypass-2fa-and-possible-sqli-2a4ea66f82c5