Mekkawy's Profile

Hacking, Developing.

View on GitHub

Account Take Over Through A CSRF Combined With An Invitation Feature & The Login Functionality.

How

While testing the API I thought about downloading the apk version of this app to see if there were other endpoints I could test further. After decompiling the apk, I noticed an endpoint that changes the email of the user. I noticed that this endpoint is open to CSRF vulnerability, but The endpoint needed additional information for the attack to be successful, and I was able to get it using the invitation feature. After this, I used the login functionality to deliver the attack in a better way and eliminate the factor of complexity.

The CSRF Vulnerability

The Invitation Feature

The Login Functionality

My Info

Intigriti : https://app.intigriti.com/researcher/profile/mekky

Yeswehack : https://yeswehack.com/hunters/mekky

Linkedin : https://www.linkedin.com/in/muhammed-mekkawy-1504821b2/

Twitter : https://twitter.com/Mekky49295157