👨‍🏫 Tutorial Bypass almost every Philippines Government and Educational Website OTP

I2Chan

Forum Expert
Kahit 8 year old na hecker ma bypass niya, sure ball. Hayst, developers and cyber specialists. Kahit ang DICT hindi secure.

This is strictly educational purposes only.



Kailangan mo parin ng account. But let's say after login, hindi ka makapasok dahil sa OTP. Ito ang bypass.

  1. Open the Network of Inspect Element. Enable the persistent logs.
  2. Login sa account.
  3. Hanapin mo yung request sa login API at icopy mo yung token mo.
    1. Pag wala ang token, it means na set siya sa cookie.
    2. If may token, it means na set siya sa header.
  4. Use a directory discovery tool to discover all API endpoints.
  5. Simply use your token at directly request sa API endpoints.
  6. Hecked.
 
Para marecognize yung account and cross-check the OTP with it. And yun or doon itself ang flaw.
Normally ang flow is after ma-verify yung otp doon palang nag-sset ng token or cookie, ngayon ko lang na-encounter yung after the user logs in nag sset na agad ng token or cookie to verify the account and otp which is uneccesary because it is sent usually in the user's account (i.e email) you don't need to verify it or the account itself kasi redundant na. Tapos usually these tokens or cookies have expiration and hindi dapat nagagamit itong mga early set token and cookies to access the website itself. If they do and if it doesn't have the expiration, I would say the developer itself is incompetent.
 
Normally ang flow is after ma-verify yung otp doon palang nag-sset ng token or cookie, ngayon ko lang na-encounter yung after the user logs in nag sset na agad ng token or cookie to verify the account and otp which is uneccesary because it is sent usually in the user's account (i.e email) you don't need to verify it or the account itself kasi redundant na. Tapos usually these tokens or cookies have expiration, if it doesn't have, I would say the developer itself is incompetent.
Yun po ang problema they don't, I think it's because masmadali siya ma implement hence we can safely assume they don't care or hindi lang sila marunong. Yung OTP rin nila, it lasts very long at walang timeout, wala rin rate limit. That's a problem kasi anyone can bruteforce it easily kahit code payan basta lang may limitation yung pattern at computable.

"the user logs in nag sset na agad ng token or cookie to verify the account and otp which is uneccesary" Not really po kasi if you verify the code, the system still needs to know para saang account siya or anong account ang ilogin afterwards. Yun lang, nag diretso sila at binigay agad without limiting yung hindi pa na-verified OTP token.
 
Yun po ang problema they don't, I think it's because masmadali siya ma implement hence we can safely assume they don't care or hindi lang sila marunong. Yung OTP rin nila, it lasts very long at walang timeout, wala rin rate limit. That's a problem kasi anyone can bruteforce it easily kahit code payan basta lang may limitation yung pattern at computable.

"the user logs in nag sset na agad ng token or cookie to verify the account and otp which is uneccesary" Not really po kasi if you verify the code, the system still needs to know para saang account siya or anong account ang ilogin afterwards. Yun lang, nag diretso sila at binigay agad without limiting yung hindi pa na-verified OTP token.
Dapat ma-häçk na ng malala para madala. jajajaja
 

About this Thread

  • 74
    Replies
  • 5K
    Views
  • 69
    Participants
Last reply from:
choitotz

Online now

Members online
1,235
Guests online
3,657
Total visitors
4,892

Forum statistics

Threads
2,325,840
Posts
29,224,845
Members
1,167,644
Latest member
Bruhman34
Back
Top