Email verification by pass on registration | Bug POC|

Поділитися
Вставка
  • Опубліковано 18 вер 2024
  • The bug is present in the email verification. where an attacker can verify any email address using the old email verification link.
    On registration, once an attacker gets the email verification link, the link will work as a master link, so they can verify any account using the same link.
    E.g link : www.etoro.com/...
    Steps To Reproduce:
    This issue can be reproduced by following these easy steps:
    Create an account.
    Setup burpsuite proxy with web browser.
    Copy the old email verification link and paste into the browser.
    Turn on the burp suite interceptor and change the Base64 encrypted email address.
    Supporting Material/References:
    verification_bypass.mp4
    Impact
    This issue can be used to bypass email verification on registration. Attackers can create accounts on behalf on any person without having access to the email account.
    I'm Umair Farooqui, a passionate software engineer and security researcher dedicated to uncovering vulnerabilities in systems worldwide. With a strong background in ethical hacking, I delve into the intricacies of cybersecurity to safeguard digital infrastructures.
    🔍 Hacking Experience:
    I specialize in discovering and responsibly disclosing critical security issues. My portfolio includes successful hacks and disclosures impacting renowned organizations such as NASA and Paytm, earning recognition and appreciation for enhancing their security postures.
    🎥 UA-cam Channel:
    On my UA-cam channel, I share Proof of Concept (PoC) videos where I demonstrate how vulnerabilities were identified and exploited. Each video provides insights into the techniques used and the impact on security.
    🌐 Connect with Me:
    - GitHub: github.com/muf...
    - Instagram: / mufazmi
    - Twitter: / mufazmi
    - HackerOne: hackerone.com/...
    - Bugcrowd: bugcrowd.com/m...
    - Google Search: www.google.com...
    - Google Search: www.google.com...
    📱 Contact Me:
    - WhatsApp: +91 9867503256
    Note: All content shared on this channel is for educational purposes only.
    🔗 Hashtags:
    #mufazmi #umairfarooqui #ethicalhacking #cybersecurity #infosec #bugbounty #securityresearch #hacker #bughunter #websecurity #pentesting #vulnerability #exploit #securityawareness #tech #coding #opensource #privacy #datasecurity #cybercrime #networksecurity #cyberattack #digitalforensics #blockchainsecurity #iotsecurity #appsec #cloudsecurity #redteam #blueteam #hackerinmumbra #mumbra #mumbrahacker #hackerkausa #mumbrahacker #itpm #hackerinsaraimeer #saraimeerhacker #saraimeer
    Join me in exploring the world of cybersecurity, one vulnerability at a time! Let's secure the digital landscape together. 💻🛡️

КОМЕНТАРІ • 11