2FA simple bypass
Last updated
Was this helpful?
Last updated
Was this helpful?
Use the given credentials wiener:peter
to log in. Once you enter the correct username and password, the application redirects you to a page asking for a 2FA code.
After entering the correct One-Time Password (OTP) for the wiener
account, you gain full access to your account. However, our goal is to bypass the 2FA for the victim's account (carlos:montoya
).
Log in using the victim's credentials carlos:montoya
. Instead of entering the OTP, manually navigate to the /my-account
page by modifying the URL in your browser. This will bypass the 2FA mechanism.
For example:
Replace the 2FA page URL (/login2
) with /my-account
.
After modifying the URL, you are successfully logged into Carlos's account without needing to provide the OTP. This confirms the 2FA bypass vulnerability.