15. Authentication Bypass Revision
15. Authentication Bypass Revision
======================
2. BMW India:
1. 99 Acres:
1. Star Quik:
Sometimes such websites show a logic flaw where 0000 OTP can be bypassed for which
the developer did not set any restrictions.
1. Stylecracker:
Sometimes websites do not have a response when the OTP is incorrect. By Trial and
Hit Method we find out that by inserting values like 1 (in this example) or true or
sometimes status code 200 or such other characters we can bypass the logic.
Here we logged in using the right OTP, intercepted the response and changed the
“id” parameter to another value so that we could log in into someone else’s account
using our correct OTP
1. Misrii:
Here again we entered the right OTP, and to log in into another user's account we
changed the “user_id” parameter’s value
Best wishes,
Rohit Gautam & Shifa Cyclewala