Lab 8: Bypassing 2FA

 I got two usernames and passwords.

  • My credentials: wiener:peter
  • Victim's credentials carlos:montoya

I started by testing the first one to see how it worked and what pages I could access when logged in to then try to access those pages


I am now gonna try to use IDOR to change the reference to Carlos to see if it would allow me but it didn’t.

At this point, I still think that I might be able to change into Carlos.

As I was logging into Carlos i used the reference to then change to Carlos.

Comments

Popular posts from this blog

Practitioner Lab 1: File path traversal, traversal sequences blocked with absolute path bypass

Practitioner Lab 7: SSRF with filter bypass via open redirection vulnerability

Practitioner Lab 4: File path traversal, validation of start of path

Practitioner Lab 5:File path traversal, validation of file extension with null byte bypass