BOOK THIS SPACE FOR AD
ARTICLE ADHello all.
Welcome back.
In this blog we will see how i finded a one of the easiest p4 bug as per bug crowd vrt(vulnerability rating taxonomy ).
BUGNAME: WEAK LOGIN FUNCTION OVER HTTP.
So let’s see how i finded this.
Step by step.
First i created a account . and i confirmed my email by clicking confirm.
it redirects to login page.
You can see in below image .this login url is loaded by http protocal.
After i clicked on login.
After clicking on login . it’s redirects me to my dashboard.
So i created a report and and submit to them .
What is the impact:
Credential Interception:Data Transmission: HTTP transmits data in plaintext, making it susceptible to interception by attackers using…