Redacted bugs #2: Privilege escalation using improper preservation of permissions during the OAuth app installation

‎

May 31, 2023 Â· 4 min Â· 837 words

Redacted bugs #1: Chaining a lack of values correlation, linear growth of attempts, and other omissions in OTP implementations to achieve 2 ATOs

This post describes two account takeover vulnerabilities w/o user interaction resulting from multiple omissions in the OTP implementations.

January 19, 2023 Â· 10 min Â· 2001 words

Multi-factor authentication security testing and possible bypasses

This post describes 11 ways of bypassing MFA.

January 9, 2020 Â· 16 min Â· 3365 words