How I Got $250 with a Weak Signup Flow

1 month ago 22
BOOK THIS SPACE FOR AD
ARTICLE AD

Raunak Gupta Aka Biscuit

Free Article Link: HERE!!!

So, here I was, browsing random apps like a professional bounty hunter (totally not procrastinating). I stumble upon this website that looks pretty legit. Naturally, I head straight for the “Sign Up” page. It’s like the front door of a house — you want to see if the lock is sturdy or, you know, if it’s more like a welcome mat for hackers.

The first red flag: the website didn’t even care if my password was “password123” I could already smell the vulnerability. But then, I noticed something juicier

The Magic Link of Doom

While signing up, I received one of those “magic links” in my email. You know, the ones that are supposed to log you in when you click them? The link looked something like this:

https://readacted.com/auth?token=dXNlcjFAZXhhbXBsZS5jb20=

Hold up. “dXNlcjFAZXhhbXBsZS5jb20=” That’s Base64. Not some super-secret cryptographic hash. It was literally my email encoded in Base64, probably the least secure “security feature” one could use.

Read Entire Article