Congratulations β€οΈβοΈ.
The course π₯·:
https://youtube.com/playlist?list=PLB12OzawmZE6Zdj6oaXy_dkMF1_uIFNWa&si=_WA9E8bMr_Z_XotO
The course π₯·:
https://youtube.com/playlist?list=PLB12OzawmZE6Zdj6oaXy_dkMF1_uIFNWa&si=_WA9E8bMr_Z_XotO
β€34π₯°3β€βπ₯2π1
Authz-ExeC is a Burp Suite extension that automatically tests authorization by replaying requests with different identities to detect IDOR, BOLA, Broken Access Control, privilege escalation, and cross-tenant vulnerabilities:
https://github.com/execiq/Authz-ExeC
https://github.com/execiq/Authz-ExeC
GitHub
GitHub - execiq/Authz-ExeC: Burp Suite extension for cross-identity & cross-tenant access-control testing β BAC, IDOR, BOLA, andβ¦
Burp Suite extension for cross-identity & cross-tenant access-control testing β BAC, IDOR, BOLA, and privilege escalation. - execiq/Authz-ExeC
β€31β€βπ₯4
β€81π₯6π€©3
Found 2 vulnerabilities:
Reward: $1,500
Critical β Authentication Bypass
High β Authentication Bypass
LinkedIn Post
Reward: $1,500
Critical β Authentication Bypass
High β Authentication Bypass
LinkedIn Post
β€59π₯4
Found a valid IDOR vulnerability in Googleπ₯π₯
https://www.facebook.com/share/1C6BgmxdJs/?mibextid=wwXIfr
https://www.facebook.com/share/1C6BgmxdJs/?mibextid=wwXIfr
β€44π₯9π1
β€86π₯14
π₯The 2 New Videos Are Live!
2FA Bypass β Empty OTP Accepted = Account Takeover:
Link
MFA Enforcement Bypass β Invite Team Members Without Enabling MFA
Link
2FA Bypass β Empty OTP Accepted = Account Takeover:
Link
MFA Enforcement Bypass β Invite Team Members Without Enabling MFA
Link
YouTube
Critical TOTP 2FA Bypass β Empty Token Accepted Leads to Account Takeover
In this video, I demonstrate a critical TOTP 2FA bypass vulnerability where the verification endpoint accepts an empty string ("") as a valid 2FA code.
By exploiting this flaw, an attacker who already knows the victim's password can bypass the TOTP verificationβ¦
By exploiting this flaw, an attacker who already knows the victim's password can bypass the TOTP verificationβ¦
β€44π₯5π1