👨‍🏫 Tutorial Bypass almost every Philippines Government and Educational Website OTP

Para marecognize yung account and cross-check the OTP with it. And yun or doon itself ang flaw.
Normally ang flow is after ma-verify yung otp doon palang nag-sset ng token or cookie, ngayon ko lang na-encounter yung after the user logs in nag sset na agad ng token or cookie to verify the account and otp which is uneccesary because it is sent usually in the user's account (i.e email) you don't need to verify it or the account itself kasi redundant na. Tapos usually these tokens or cookies have expiration and hindi dapat nagagamit itong mga early set token and cookies to access the website itself. If they do and if it doesn't have the expiration, I would say the developer itself is incompetent.
 
Normally ang flow is after ma-verify yung otp doon palang nag-sset ng token or cookie, ngayon ko lang na-encounter yung after the user logs in nag sset na agad ng token or cookie to verify the account and otp which is uneccesary because it is sent usually in the user's account (i.e email) you don't need to verify it or the account itself kasi redundant na. Tapos usually these tokens or cookies have expiration, if it doesn't have, I would say the developer itself is incompetent.
Yun po ang problema they don't, I think it's because masmadali siya ma implement hence we can safely assume they don't care or hindi lang sila marunong. Yung OTP rin nila, it lasts very long at walang timeout, wala rin rate limit. That's a problem kasi anyone can bruteforce it easily kahit code payan basta lang may limitation yung pattern at computable.

"the user logs in nag sset na agad ng token or cookie to verify the account and otp which is uneccesary" Not really po kasi if you verify the code, the system still needs to know para saang account siya or anong account ang ilogin afterwards. Yun lang, nag diretso sila at binigay agad without limiting yung hindi pa na-verified OTP token.
 
Yun po ang problema they don't, I think it's because masmadali siya ma implement hence we can safely assume they don't care or hindi lang sila marunong. Yung OTP rin nila, it lasts very long at walang timeout, wala rin rate limit. That's a problem kasi anyone can bruteforce it easily kahit code payan basta lang may limitation yung pattern at computable.

"the user logs in nag sset na agad ng token or cookie to verify the account and otp which is uneccesary" Not really po kasi if you verify the code, the system still needs to know para saang account siya or anong account ang ilogin afterwards. Yun lang, nag diretso sila at binigay agad without limiting yung hindi pa na-verified OTP token.
Dapat ma-häçk na ng malala para madala. jajajaja
 

About this Thread

  • 75
    Replies
  • 4K
    Views
  • 70
    Participants
Last reply from:
choitotz

Online now

Members online
1,260
Guests online
1,426
Total visitors
2,686

Forum statistics

Threads
2,268,801
Posts
28,924,146
Members
1,243,061
Latest member
peaceminusone
Back
Top