Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



   6690

BROKEN AUTHENTICATION(Ez Access to Admin Of a Site)

by Pentester708 - 14 November, 2019 - 03:31 AM
This post is by a banned member (Pentester708) - Unhide
652
Posts
482
Threads
5 Years of service
#1
LEAVE A LIKE MATES THANKS

Started a New Shit Yesterday(Got a Hit That Very Moment)
Its Broken Authentication(OWASP TOP 10)
I wont be going much technical into it for all the public taken into consideration

It is a way to bypass the authentication in a website without entering the username/password .As the name says broken authentication means the authentication flow set by that website has some other way round to get in

Example: 1. www.xyz.com/admlogin has an authentication set
2. Inside that admin login there is a page like www.xyz.com/admlogin/editdetails.aspx
3. So Instead of going to /admlogin you directly went to the other URL and boom you are inside the admin login without having to enter the username and password(Thats just one basic example)


Now here is the website:
Hidden Content
You must register or login to view this content.



Here is the inside page URL: Just add /admin/home.php to the above URL and You are an admin with all the permissions

Note: You have the admin access to only those pages which are having broken authentication, Not to all
If you tracerse to any other page it might ask you the admin credentials cuz it is secured by this vulnerability
[Image: Udpc9Lb.gif]
Telegram: https://t.me/candycainlobbies
Ad by brocain
This post is by a banned member (muliusa) - Unhide
muliusa  
Registered
31
Posts
1
Threads
5 Years of service
#2
thanks dd
This post is by a banned member (anksark) - Unhide
This post is by a banned member (junior2022) - Unhide
9
Posts
0
Threads
5 Years of service
#4
dddddddddddddd
This post is by a banned member (redyopa1252) - Unhide
13
Posts
0
Threads
5 Years of service
#5
thanks
This post is by a banned member (KazuyaMishima) - Unhide
This post is by a banned member (rosen) - Unhide
rosen  
Registered
11
Posts
0
Threads
5 Years of service
#7
(14 November, 2019 - 03:31 AM)Pentester708 Wrote: Show More
LEAVE A LIKE MATES THANKS

Started a New Shit Yesterday(Got a Hit That Very Moment)
Its Broken Authentication(OWASP TOP 10)
I wont be going much technical into it for all the public taken into consideration

It is a way to bypass the authentication in a website without entering the username/password .As the name says broken authentication means the authentication flow set by that website has some other way round to get in

Example: 1. www.xyz.com/admlogin has an authentication set
2. Inside that admin login there is a page like www.xyz.com/admlogin/editdetails.aspx
3. So Instead of going to /admlogin you directly went to the other URL and boom you are inside the admin login without having to enter the username and password(Thats just one basic example)


Now here is the website:

Here is the inside page URL: Just add /admin/home.php to the above URL and You are an admin with all the permissions

Note: You have the admin access to only those pages which are having broken authentication, Not to all
If you tracerse to any other page it might ask you the admin credentials cuz it is secured by this vulnerability

wooooooooow
This post is by a banned member (guestmaster) - Unhide

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 1 Guest(s)