[ BUG BOUNTY ] Allowing Register With Official Domain

Danang Tri Atmaja
1 min readJul 2, 2019

--

Hallo teman-teman researcher bagaimana kabarnya ? semoga senantiasa sehat selalu dan diberikan kelancaran dalam aktifitasnya.

Hall of Fame

Saya ingin share ketika saya mendapatkan sebuah bugs yang termasuk didalam kategori “ Insufficient Security Configurability > Lack of Verification Email “. Bug ini termasuk simple untuk mendapatkannya, berikut STR ( Step to Reproduce ) :

==============

Proof of Concept :

  1. Go www.redacted.com
  2. Go Register Account Page
  3. Register email with : xxxxx@redacted.com

-> eg: adminsuper@redacted.com

4. Create Account

5. Boom ! you sign-in enter the system ! with account without verification

adminsuper@redacted.com

===============

Security Impact is Email addresses can be sign-in using main domain without verification, and this is can do an action with official email

“sometimes you can enter the system without verification”

Referensi :

Reward : Hall of Fame

--

--

Danang Tri Atmaja
Danang Tri Atmaja

Written by Danang Tri Atmaja

IT Security { enthusiast } — Penetration Tester PT. ITSEC Asia

No responses yet