Skip to main content
XsiSec.com
HomeReposBlogProjectsPortfolio
© 2026 XsiSec.com
Security rules |security.txt
Updated 2026-08-15 · v1.0.0+2026-08-14.82f92cb · 82f92cb
← Back to overview
Security article

2FA Broken Logic

2FA Broken Logic: Exploit a broken 2FA flow to log in as carlos starting from a valid session for wiener:peter. • PortSwigger • Authentication • mfa, broken-logic

2022-06-083 tags
Tags

🎯 Objective

Exploit a broken 2FA flow to log in as carlos starting from a valid session for wiener:peter.

🧭 Scope / Setup

  • Tooling: Burp Suite (HTTP history, Repeater, Intruder)
  • Accounts: wiener:peter (known), target to impersonate: carlos

🔎 Steps

  1. Log in as wiener:peter. Capture POST /login2 containing the username parameter. Login Request
  2. Log out.
  3. Send GET /login2 to Repeater and change the account to carlos to trigger a 2FA code for Carlos. Burp Repeater Carlos
  4. Log back in as wiener:peter and submit any 2FA code; send POST /login2 to Intruder.
  5. Set verify=carlos and brute‑force the numeric OTP. Burp Intruder Intruder Payload
  6. Identify the 302 redirect among 200s → open in browser → authenticated as Carlos. Logged in as Carlos

🧪 Why This Works

  • 2FA generation and verification are decoupled from the authenticated user session.
  • Lack of binding between OTP and the initiating user enables account pivot.

✅ Outcome

  • Successful account takeover of Carlos due to flawed 2FA validation/binding.

🛡️ Mitigations

  • Bind OTP to user and session; include nonce tied to login flow.
  • Rate‑limit and lockout after repeated failures; monitor anomalies.
  • Use short‑lived OTP with strict server‑side state checks.

📝 Notes

  • Always verify OTP consumption is scoped to the original authentication transaction.
Navigate

In this post

  1. 01🎯 Objective
  2. 02🧭 Scope / Setup
  3. 03🔎 Steps
  4. 04🧪 Why This Works
  5. 05✅ Outcome
  6. 06🛡️ Mitigations
  7. 07📝 Notes
Search
Explore

Popular tags

Browse all 30 tags

Comments

0 comments

No comments yet — be the first to comment.