Back to directory
WRITEUP #4606

Account Takeover via OTP Bruteforce (Apigee API)

RCEOTP bypassBruteforceLack of rate limiting
byVishnuraj
Program
-
Published
Jun 13, 2020
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://medium.com/@vishnu0002/account-takeover-via-otp-bruteforce-apigee-api-9b5481c642df
RELATED WRITEUPS
Unlocking the Weak Spot: Exploiting Insecure Password Reset Tokens
RCEBruteforce
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
[2,500$ Bug Bounty Write-Up] Remote Code Execution (RCE) via unclaimed Node package
RCEDependency confusion
Attacking PowerShell CLIXML Deserialization
DeserializationInsecure deserialization
Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOS
RCEArbitrary file write

Built with ❤️ by Shubham Rawat