Post

Week #2 March

Week #2 March

Table of Contents


The Bug

I don’t have any bugs to report, I’m just enjoying the colors of HOLI.


Hack The Box

I tried to solve seasonal Machine named as DOG, it was an easy challenge but I didn’t get the flag. So yeah looking for write-up.


The Notion Notes

I created a Notion database for my reports so that I don’t have to remember which report is pending is which got triaged.


The Web Application Fundamentals

I solved 2 rooms Authentication Bypass and IDOR on TryHackMe.


Write-Up

I read some random write-ups about authentication bypass one of them is Swapping of Attacker and Victim Email leads to OTP bypass.

A little bit About this OTP Bypass WriteUp:

  1. If Victim login using email victim@gmail.com there is 3 minutes of tiem for OTP, after 3 minutes OTP is expired.
  2. At the same time If attacker login with attacker@gmail.com and the attacker get his own OTP.
  3. The attacker uses victim email at the same time to login and he gives the OTP of his own instead of victim. The attacker loggedin with victim@gmail.com successfully with wrong OTP.

The Next Week

  • Bug Hunting
  • The Web Fundamentals Room
  • Hack The Box Seasonal Machine
  • Reading Write-Ups

Thank you for reading and If you have any questions or suggestions ask me @ghost__man01 or @sid-d-hant here.

This post is licensed under CC BY 4.0 by the author.