Email Verification Bypass during Account Creation | Insecure Design
Hello! While hunting on a public program, I discovered a simple flaw that made it possible to create an account without verifying its email address. The website contained an embedded app that required users to verify a phone number. After entering the code, the application required submitting personal information before verifying an email. An unusual request was made to http://redacted.us-east-1.aws.squid.cloud/query/batchQueries. It fetched user profile information from a local instance of Firebase even though registration was still in progress. Strange. I took a closer look and noticed the email verification token was included as profile data.Structure of verificationToken Sending a GET request to https://www.redacted.com/auth/verify?lid=redact ed&token=eyJlbWFpbCI6InJ2YW53YXJ0QHdlYXJlaGFja2Vyb25lLmNvbSIsImV4cCI6MTc0NTM4MjQ1NDQxOSwic2FsdCI6Im1lcTRsNWtxMWMifQ== finalized account creation. I found this endpoint after previously creating an account. This vulnerability is an example of security through obscurity. Using it would would make it possible to register with any unused email address and potentially impersonate other users or staff.Remediation Prohibit users from accessing profile data until registration is complete. If that is not possible, consider moving verification tokens to a table in Firebase with restricted access. Email Verification Bypass during Account Creation | Insecure Design was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
Hello! While hunting on a public program, I discovered a simple flaw that made it possible to create an account without verifying its email address. The website contained an embedded app that required users to verify a phone number. After entering the code, the application required submitting personal information before verifying an email. An unusual request was made to http://redacted.us-east-1.aws.squid.cloud/query/batchQueries. It fetched user profile information from a local instance of Firebase even though registration was still in progress. Strange. I took a closer look and noticed the email verification token was included as profile data.Structure of verificationToken Sending a GET request to https://www.redacted.com/auth/verify?lid=redact ed&token=eyJlbWFpbCI6InJ2YW53YXJ0QHdlYXJlaGFja2Vyb25lLmNvbSIsImV4cCI6MTc0NTM4MjQ1NDQxOSwic2FsdCI6Im1lcTRsNWtxMWMifQ== finalized account creation. I found this endpoint after previously creating an account. This vulnerability is an example of security through obscurity. Using it would would make it possible to register with any unused email address and potentially impersonate other users or staff.Remediation Prohibit users from accessing profile data until registration is complete. If that is not possible, consider moving verification tokens to a table in Firebase with restricted access. Email Verification Bypass during Account Creation | Insecure Design was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
Nothing changed… except for one detail. And that was enough to hack
Sometimes, hacking doesn’t require any exploit… just good observation.Continue reading on InfoSec Write-ups »
Read more...
Sometimes, hacking doesn’t require any exploit… just good observation.Continue reading on InfoSec Write-ups »
Read more...
Medium
Nothing changed… except for one detail. And that was enough to hack
Sometimes, hacking doesn’t require any exploit… just good observation.
How I discovered a hidden user thanks to server responses ?
My first real step into web hacking and it wasn’t what i thought it would be.Continue reading on InfoSec Write-ups »
Read more...
My first real step into web hacking and it wasn’t what i thought it would be.Continue reading on InfoSec Write-ups »
Read more...
Medium
🔍 How I discovered a hidden user thanks to server responses ?
My first real step into web hacking and it wasn’t what i thought it would be.
I Used AI to Write a Payload… And It Worked (Sort of)
🎯Free Article LinkContinue reading on InfoSec Write-ups »
Read more...
🎯Free Article LinkContinue reading on InfoSec Write-ups »
Read more...
Medium
I Used AI to Write a Payload… And It Worked (Sort of) 🤖💥
🎯Free Article Link
Bug Bounty: failure experience records
Bug bounty requires luck in addition to skills, because the final result is only yes or no, there is no middle option.Continue reading on Medium »
Read more...
Bug bounty requires luck in addition to skills, because the final result is only yes or no, there is no middle option.Continue reading on Medium »
Read more...
Medium
Bug Bounty: failure experience records
Bug bounty requires luck in addition to skills, because the final result is only yes or no, there is no middle option.
I Used AI to Write a Payload… And It Worked (Sort of)
🎯Free Article LinkContinue reading on InfoSec Write-ups »
Read more...
🎯Free Article LinkContinue reading on InfoSec Write-ups »
Read more...
Medium
I Used AI to Write a Payload… And It Worked (Sort of) 🤖💥
🎯Free Article Link
Arjun: The Ultimate Parameter Discovery Tool For Bug Hunters
Uncovering Hidden Secrets in Web Apps with ArjunContinue reading on Medium »
Read more...
Uncovering Hidden Secrets in Web Apps with ArjunContinue reading on Medium »
Read more...
Medium
Arjun: The Ultimate Parameter Discovery Tool For Bug Hunters
Uncovering Hidden Secrets in Web Apps with Arjun
Hijacking Trust: The Parallels Between Use-After-Free and Insecure Deserialization
https://medium.com/@MasoudAbdaal/hijacking-trust-the-parallels-between-use-after-free-and-insecure-deserialization-a12c587a2987?source=rss------bug_bounty-5
https://medium.com/@MasoudAbdaal/hijacking-trust-the-parallels-between-use-after-free-and-insecure-deserialization-a12c587a2987?source=rss------bug_bounty-5
I Used AI to Write a Payload… And It Worked (Sort of)
https://infosecwriteups.com/i-used-ai-to-write-a-payload-and-it-worked-sort-of-55b6860d8be9?source=rss------bug_bounty-5
https://infosecwriteups.com/i-used-ai-to-write-a-payload-and-it-worked-sort-of-55b6860d8be9?source=rss------bug_bounty-5
🎯Free Article LinkContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/i-used-ai-to-write-a-payload-and-it-worked-sort-of-55b6860d8be9?source=rss------bug_bounty-5)
Bug Bounty: failure experience records
https://medium.com/@smilemil/bug-bounty-failure-experience-records-62e928efd54a?source=rss------bug_bounty-5
Bug bounty requires luck in addition to skills, because the final result is only yes or no, there is no middle option.Continue reading on Medium » (https://medium.com/@smilemil/bug-bounty-failure-experience-records-62e928efd54a?source=rss------bug_bounty-5)
https://medium.com/@smilemil/bug-bounty-failure-experience-records-62e928efd54a?source=rss------bug_bounty-5
Bug bounty requires luck in addition to skills, because the final result is only yes or no, there is no middle option.Continue reading on Medium » (https://medium.com/@smilemil/bug-bounty-failure-experience-records-62e928efd54a?source=rss------bug_bounty-5)
Arjun: The Ultimate Parameter Discovery Tool For Bug Hunters
https://medium.com/@lancersiromony/arjun-the-ultimate-parameter-discovery-tool-for-bug-hunters-6ead8aaf295b?source=rss------bug_bounty-5
Uncovering Hidden Secrets in Web Apps with ArjunContinue reading on Medium » (https://medium.com/@lancersiromony/arjun-the-ultimate-parameter-discovery-tool-for-bug-hunters-6ead8aaf295b?source=rss------bug_bounty-5)
https://medium.com/@lancersiromony/arjun-the-ultimate-parameter-discovery-tool-for-bug-hunters-6ead8aaf295b?source=rss------bug_bounty-5
Uncovering Hidden Secrets in Web Apps with ArjunContinue reading on Medium » (https://medium.com/@lancersiromony/arjun-the-ultimate-parameter-discovery-tool-for-bug-hunters-6ead8aaf295b?source=rss------bug_bounty-5)
Hostile Host Headers: How I Hijacked the App with One Sneaky Header
Hey there!😊Continue reading on Medium »
Read more...
Hey there!😊Continue reading on Medium »
Read more...
Medium
🧩 Hostile Host Headers: How I Hijacked the App with One Sneaky Header 🧠📬
Hey there!😊
From 0 to Hacker Hero
My Bug Bounty Journey Starts with CTFs & Curiosity 🧠🔍Continue reading on Medium »
Read more...
My Bug Bounty Journey Starts with CTFs & Curiosity 🧠🔍Continue reading on Medium »
Read more...
Medium
💻 From 0 to Hacker Hero 🚀
My Bug Bounty Journey Starts with CTFs & Curiosity 🧠🔍
Mastering Linux Privilege Escalation: Part 2 — Cron, Sudo, Kernel, and PATH Exploits
Series: Part 2 of 3 — Advanced Real-World Post-Exploitation for Ethical HackersContinue reading on Medium »
Read more...
Series: Part 2 of 3 — Advanced Real-World Post-Exploitation for Ethical HackersContinue reading on Medium »
Read more...
Medium
Mastering Linux Privilege Escalation: Part 2 — Cron, Sudo, Kernel, and PATH Exploits
Series: Part 2 of 3 — Advanced Real-World Post-Exploitation for Ethical Hackers
How I Bypassed Template Escaping and Triggered a Reflected XSS Popup
🌐 IntroductionContinue reading on Medium »
Read more...
🌐 IntroductionContinue reading on Medium »
Read more...
Medium
🛑 How I Bypassed Template Escaping and Triggered a Reflected XSS Popup
By @zoningxtr
Bypassed the Invite Flow, Gained Admin Access
الحمد لله الذي عَلَّمَ بالقلم.. عَلَّمَ الإنسانَ ما لم يَعْلَم والصلاةُ والسلامُ على خيرِ مُعَلِّمي الناسِ الخير محمد أما بعدContinue reading on Medium »
Read more...
الحمد لله الذي عَلَّمَ بالقلم.. عَلَّمَ الإنسانَ ما لم يَعْلَم والصلاةُ والسلامُ على خيرِ مُعَلِّمي الناسِ الخير محمد أما بعدContinue reading on Medium »
Read more...
Medium
Bypassed the Invite Flow, Gained Admin Access
الحمد لله الذي عَلَّمَ بالقلم.. عَلَّمَ الإنسانَ ما لم يَعْلَم والصلاةُ والسلامُ على خيرِ مُعَلِّمي الناسِ الخير محمد أما بعد
How I’m Learning Web3.0(Blockchain) Bug Bounties from Scratch And Sharing Everything.
From smart contract novice to ambitious Web3(Blockchain) Hacker, follow along as I learn, break, and share my journey.Continue reading on Medium »
Read more...
From smart contract novice to ambitious Web3(Blockchain) Hacker, follow along as I learn, break, and share my journey.Continue reading on Medium »
Read more...
Medium
How I’m Learning Web3.0(Blockchain) Bug Bounties from Scratch And Sharing Everything.
From smart contract novice to ambitious Web3(Blockchain) Hacker, follow along as I learn, break, and share my journey.