Skip to main content

How I bypassed the OTP verification process?

It’s been so long since I posted any article, partially because I was tired and taking a pleasant summer break. I was reading this particular article

How I could have booked movie tickets through other user accounts by Bharathvaj Ganesan


After reading this I realised that I have had always tried different ways to try and bypass the login credentials but never those which had OTP verification process. So this article gave a me this feel that online profiles which have inbuilt OTP verification process is not super secure as well and from there onward I tried to carry out some attack on a website that uses OTP verification process.

Let’s dig in!


I started my attack on this website let’s say example.com, here I carried out my attack in two phase. Can I create a profile using a mobile no. that I don’t own? ( Identity theft ) Can I get access to the account of a person, if all I know is their username or mobile number? ( How I bypassed the OTP verification process? Part — 2 ) The first hack So to understand how to create a profile and how the system of OTP works on that particular website I went ahead and created my account. While I was doing that I took notice as to how the website worked?. Once done then I carried it out again for the another number that I own but this time the whole Idea was to create the account without having to touch my phone in anyway in which the sim was inserted. So, here is how I began doing the hack. I inserted all the details as it should be. Now as I was done with it, I received an OTP on my phone instantly to verify and complete the process of a creating the account.
Burp Suite on! I was presented with this and had to put in the OTP that I had just received on my mobile. I turned intercept mode on, and captured the packet which was being sent over as a request packet to the server.

Comments

Popular posts from this blog

Professional Hacker

The bestselling  author   Kishlay Nayan  is a tech junkie who loves tinkering with computers, gadgets and everything tech. He has hosted a popular show on MTV India called What the Hack!, where he gave tips, tricks and tweaks to get more out of technology and the Internet and now has his own YouTube channel called  Geek On The Loose . 

Online hacking Course

Advantages of online training Interaction with the best hackers as teacher Learn from the comfort of your home Participants must have a valid e-mail id to register. Get full access to our books, tools & several other resouces from our digital library You can choose your date & time, as per your convenience One teacher for each student, individual attention Pay via Bank Wire (TT) or Western Union EMI facilities available. Ethical Hacking (Advanced Level) For course details visit:  Duration = 4 hours x 12 days                                          Weekend, evening, weekdays - Classes Available                            ...