How Inadequate Authentication Logic Led to an MFA Bypass and Account Takeover
ID: cfa243ec-ff7c-54f1-a815-479bf183f8c1
STIX ID: report--cfa243ec-ff7c-54f1-a815-479bf183f8c1
Feed Name: HackerOne Blog
Threat Score
This report describes an authentication security write-up that documents a critical MFA bypass affecting Drugs.com: the application issued full session cookies before verifying the one-time MFA code, allowing an attacker to delete a client-side cookie (bb_refresh) and proceed as an authenticated user. The post includes reproduction steps, discusses improper session management as the root cause, and provides mitigation guidance and general authentication best practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
