How i finded a p4 as per bugcrowd.

6 hours ago 6
BOOK THIS SPACE FOR AD
ARTICLE AD

loyalonlytoday

OSINT Team

Hello all.

Welcome back.

In this blog we will see how i finded a one of the easiest p4 bug as per bug crowd vrt(vulnerability rating taxonomy ).

BUGNAME: WEAK LOGIN FUNCTION OVER HTTP.

So let’s see how i finded this.

Step by step.

First i created a account . and i confirmed my email by clicking confirm.

it redirects to login page.

You can see in below image .this login url is loaded by http protocal.

After i clicked on login.

After clicking on login . it’s redirects me to my dashboard.

So i created a report and and submit to them .

What is the impact:

Credential Interception:Data Transmission: HTTP transmits data in plaintext, making it susceptible to interception by attackers using…
Read Entire Article