That Time a Bank Blocked My Account and Still Handed Me a Token
A four digit OTP, a ten minute lockout, and a backend that never got the memo. The story of the laziest brute force I ever ran turning into an auth bypass.
A four digit OTP, a ten minute lockout, and a backend that never got the memo. The story of the laziest brute force I ever ran turning into an auth bypass.
A messy little bug where a URL inside a URL made the server phone a stranger, then reflect whatever it said straight into the page.