INFILTRA
Open in Telegram
This is a ASHM Public Channel Thanks for joinig if not join I'm invited you join my channel and suggested you can invite your friend joining our Channel DM: @ashmsec Our Facebook Page: https://www.facebook.com/ITZ.ASHM
Show more1 010
Subscribers
No data24 hours
-57 days
-430 days
Posts Archive
1 010
Broken Authentication To Email Verification Bypass (P4) :
category : P4 >> Broken Authentication and Session Management >> Failure to Invalidate Session >> On Password Reset and/or Change
1)First You need to make a account & You will receive a Email verification link.
2)Application in my case give less Privileges & Features to access if not verified.
3)Logged into the Application & I changed the email address to Email B.
4)A Verification Link was Sent & I verified that.
5) Now I again Changed the email back to the Email I entered at the time of account creation.
6) It showed me that my Email is Verified.
7) Hence, A successful email verification Bypassed as I hadn't Verified the Link that was sent to me at the time of account creation still my email got verified.
8)Didn't Receive any code again for verification when I changed back my email & When I opened the account it showed in my Profile that its Verified Email.
Impact: Email Verification was bypassed due to a Broken Authentication Mechanism, Thus more Privileged accounts can be accessed by an attacker making the website prone to Future Attacks.
1 010
Broken-Link Hijacking
Steps
1. Manually find and click external links on the target site ( For Example:- Some Links to Social Media Accounts or Some external Media Link)
2. While Doing Manual work also put the (https://github.com/stevenvachon/broken-link-checker) in the background using the below Command in the terminal.
blc -rof --filter-level 3 https://target.com/
Output will be like Something:
─BROKEN─ https://www.linkedin.com/company/rana/ (HTTP_999)
3. Now you need to check if a company has the page or not , if no then register as the company or try to get that username or URL.
1 010
🧬Private DNS List
1. Cloudflare(1.1.1.1):
#Standard:
1dot1dot1dot1.cloudflare-dns.com
#Malware and adult content blocking:
family.cloudflare-dns.com
#Malware blocking only:
security.cloudflare-dns.com
2. GoogleDNS(8.8.8.8):
dns.google
3. Quad9DNS(9.9.9.9):
#Standard:
dns.quad9.net
#Unsecured:
dns10.quad9.net
#ECS support:
dns11.quad9.net
4. CleanBrowsingDNS:
#Default:
doh.cleanbrowsing.org
#Family Filter:
family-filter-dns.cleanbrowsing.org
#Adult Filter:
adult-filter-dns.cleanbrowsing.org
#Security Filter:
security-filter-dns.cleanbrowsing.org
5. NextDNS:
#Ultra-low latency:
dns.nextdns.io
#Anycast:
anycast.dns.nextdns.io
6. AdguardDNS:
#Default:
dns.adguard-dns.com
#Family Protection:
dns-family.adguard.com
#Non-filtering;
dns-unfiltered.adguard.com
7. OpenDNS:
dns.opendns.com
8. RedfishDNS:
dns.rubyfish.cn
9. SwitchDNS:
dns.switch.ch
10. FutureDNS:
dns.futuredns.me
11. Comss.oneDNS:
#West DNS Server (Main):
dns.comss.one
#East DNS Server (Siberia and Far East):
dns.east.comss.one
12. CIRAShieldDNS:
#Private:
family.canadianshield.cira.ca
#Protected & Family:
protected.canadianshield.cira.ca
13. BlahDNS:
#Finland:
dot-fi.blahdns.com
#Japan:
dot-jp.blahdns.com
#Germany:
dot-de.blahdns.com
14. SnopytaDNS:
fi.dot.dns.snopyta.org
15. DNSForFamily:
dns-dot.dnsforfamily.com
16. CZ.NIC ODVR:
odvr.nic.cz
17. AliDNS:
dns.alidns.com
18. CFIEC Public DNS:
dns.cfiec.net
19. 360 Secure DNS:
dot.360.cn
20. IIJ.JP DNS:
public.dns.iij.jp
21. DNSPod Public DNS+:
dot.pub
22. Privacy-First DNS:
#Singapore:
dot.tiarap.org
#Japan:
jp.tiar.app
23. OSZX DNS:
dns.oszx.co
24. PumpleX server:
dns.pumplex.com
25. Applied Privacy DNS:
dot1.applied-privacy.net
26. DeCloudUs DNS:
dns.decloudus.com
27. Lelux DNS:
resolver-eu.lelux.fi
28. DNS Forge:
dnsforge.de
29. Fondation Restena DNS:
kaitain.restena.lu
30. FFMUC DNS:
dot.ffmuc.net
31. Digitale Gesellschaft DNS:
dns.digitale-gesel
1 010
OTP Bypass on Register account via Response manipulation
FIRST METHOD:
1. Register account with mobile number and request for OTP.
2. Enter incorrect OTP and capture the request in Burpsuite.
3. Do intercept response to this request and forward the request.
4. response will be:
{"verificationStatus":false,"mobile":9075235397","profileId":"84352822"}
Change this response to:
{"verificationStatus":true,"mobile":9075235397","profileId":"84352822"}
5. And forward the response.
6. You will be logged in to the account.
SECOND METHOD:
1. Go to login and wait for OTP pop up.
2. Enter incorrect OTP and capture the request in Burpsuite.
3. Do intercept response to this request and forward the request.
4. response will be error
5. Change this response to success
6. And forward the response.
7. You will be logged in to the account.
THIRD METHOD:
1.Register 2 accounts with any 2 mobile number(first enter right otp)
2.Intercept your request
3.click on action -> Do intercept -> intercept response to this request.
4.check what the message will display like status:1
5.Follow the same procedure with other account but this time enter wrong otp
6.Intercept respone to the request
7.See the message like you get status:0
8.Change status to 1 i.e, status:1 and forward the request if you logged in means you just done authentication bypass.
1 010
Factor Bypass Techniques :
1. Response Manipulation
2. Status Code Manipulation
3. 2FA Code Leakage In Response
4. 2FA Code Resuablity
5. Lack of Brute-Force Protection
6. Missing 2FA Code Integrity Validation
7. CSRF on 2FA Disabling
8. Password Reset Disable 2FA
9. Backup Code Abuse
10. Clickjacking on 2FA Disabling Page
11. Enabling 2FA doesn't expire Previously active Sessions
12. Bypass 2FA with null or 000000
1 010
Email Verification Bypass (P3/P4)
1)First You need to Create an account with Your Own Email Address.
2)After Creating An Account A Verification Link will be sent to your account.
3)Dont Use The Email Verification link. Change Your Email to Victim's Email.
4)Now Go in Your Email and Click on Your Own Email Verification Link.
5)if the Victim's Email Get Verified then This is a Bug.
1 010
🌟 FREE Exam Voucher ISC2 CC 🌟
✅ Exam Voucher: CC1M12312024
✅ Link https://www.isc2.org/landing/1mcc
1 010
╭ SKILLSHARE BIN ✅
│
│#Tested ✅
│
├ BIN -
545285370545xxxx
├ EXP - 11|2027
│
├ IP - USA (🇺🇸)
├ ZIPCODE - 10001
│
├ LINK - Skillshare.com
├ CODE - BETHEREINFIVE
│( 2 Months Promo Code )
│
│[ GEN WORKS SMOOTHLY ]
│