Back to directory
WRITEUP #4004

Full account takeover worth $1000 Think out of the box

Auth BypassAccount takeoverCSRFIDOR
by@tabaahi_(Mohsin Khan)
Bounty
1,000
Program
-
Published
Feb 15, 2021
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://mokhansec.medium.com/full-account-takeover-worth-1000-think-out-of-the-box-808f0bdd8ac7
RELATED WRITEUPS
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
CSRF Bypass Using Domain Confusion Leads To ATO
CSRFAccount takeover
Instagram and Meta 2FA Bypass by Unprotected Backup Code Retrieval in Accounts Center
Auth Bypass2FA / MFA bypass
Forced SSO Session Fixation
Auth BypassSSO
Account takeover on 8 years old public program
Auth BypassAccount takeover

Built with ❤️ by Shubham Rawat