Thread Reader
Share this page!
×
Post
Share
Email
Enter URL or ID to Unroll
×
Unroll Thread
You can paste full URL like: https://x.com/threadreaderapp/status/1644127596119195649
or just the ID like: 1644127596119195649
How to get URL link on X (Twitter) App
On the Twitter thread, click on
or
icon on the bottom
Click again on
or
Share Via icon
Click on
Copy Link to Tweet
Paste it above and click "Unroll Thread"!
More info at
Twitter Help
Karan Chaudhary ✨
@0xKaran
Cyber Security Researcher ⚡
Subscribe
Save as PDF
Jan 20, 2022
•
11 tweets
•
3 min read
A bugbounty threads about OTP related hunting
I test these whenever I encounter with OTP related functionalities like email or phone confirmation, password reset, login with OTPs etc.
#bugbounty
#bugbountytips
#bugbountytip
#hacking
#cybersecurity
#infosec
#bughunting
1/n
2/n
1.
Bruteforce OTP (tool : Burp intruder)
2.
Developers implement additional parameters to protect their application from bruteforce attack.
eg. LoginAttempt=3 or wrong_attempt_left=1, modify or remove these parameters