Week #2 March
Week #2 March
Table of Contents
The Bug
I don’t have any bugs to report, I’m just enjoying the colors of HOLI.
Hack The Box
I tried to solve seasonal Machine named as DOG, it was an easy challenge but I didn’t get the flag. So yeah looking for write-up.
The Notion Notes
I created a Notion database for my reports so that I don’t have to remember which report is pending is which got triaged.
The Web Application Fundamentals
I solved 2 rooms Authentication Bypass and IDOR on TryHackMe.
Write-Up
I read some random write-ups about authentication bypass one of them is Swapping of Attacker and Victim Email leads to OTP bypass.
A little bit About this OTP Bypass WriteUp:
- If Victim login using email victim@gmail.com there is 3 minutes of tiem for OTP, after 3 minutes OTP is expired.
- At the same time If attacker login with attacker@gmail.com and the attacker get his own OTP.
- The attacker uses victim email at the same time to login and he gives the OTP of his own instead of victim. The attacker loggedin with victim@gmail.com successfully with wrong OTP.
The Next Week
- Bug Hunting
- The Web Fundamentals Room
- Hack The Box Seasonal Machine
- Reading Write-Ups
Thank you for reading and If you have any questions or suggestions ask me @ghost__man01 or @sid-d-hant here.
This post is licensed under CC BY 4.0 by the author.
