Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



   6697

BROKEN AUTHENTICATION(Ez Access to Admin Of a Site)

by Pentester708 - 14 November, 2019 - 03:31 AM
This post is by a banned member (Jxdskii) - Unhide
Jxdskii  
Registered
444
Posts
13
Threads
5 Years of service
#9
You have the admin access to only those pages which are having broken authentication, Not to all
If you tracerse to any other page it might ask you the admin credentials cuz it is secured by this vulnerability
This post is by a banned member (ninja2415) - Unhide
ninja2415  
Infinity
65
Posts
4
Threads
4 Years of service
#10
checking this out
This post is by a banned member (Pentester708) - Unhide
652
Posts
482
Threads
5 Years of service
#11
This is a bump
[Image: Udpc9Lb.gif]
Telegram: https://t.me/candycainlobbies
Ad by brocain
This post is by a banned member (marsbros140) - Unhide
This post is by a banned member (wwqerfsdve12e) - Unhide
This post is by a banned member (harry_potter) - Unhide
This post is by a banned member (xFadi) - Unhide
xFadi  
Registered
34
Posts
0
Threads
5 Years of service
#15
(14 November, 2019 - 03:31 AM)Pentester708 Wrote: Show More
LEAVE A LIKE MATES THANKS

Started a New Shit Yesterday(Got a Hit That Very Moment)
Its Broken Authentication(OWASP TOP 10)
I wont be going much technical into it for all the public taken into consideration

It is a way to bypass the authentication in a website without entering the username/password .As the name says broken authentication means the authentication flow set by that website has some other way round to get in

Example: 1. www.xyz.com/admlogin has an authentication set
2. Inside that admin login there is a page like www.xyz.com/admlogin/editdetails.aspx
3. So Instead of going to /admlogin you directly went to the other URL and boom you are inside the admin login without having to enter the username and password(Thats just one basic example)


Now here is the website:

Here is the inside page URL: Just add /admin/home.php to the above URL and You are an admin with all the permissions

Note: You have the admin access to only those pages which are having broken authentication, Not to all
If you tracerse to any other page it might ask you the admin credentials cuz it is secured by this vulnerability

5hqnwjww
This post is by a banned member (lolitsme) - Unhide
lolitsme  
Registered
23
Posts
0
Threads
5 Years of service
#16
Bro what the hell

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 1 Guest(s)