Mekkawy's Profile

Hacking, Developing.

View on GitHub

Account Takeover Through Open Redirect

How:

The program had an endpoint that was open to redirection vulnerability. By combining this vulnerability with authentication functionality, I was able to take over the user’s account.

Open Redirection Vulnerability:

Original Request

alt text

Steps

Exploited Request

alt text

Exploiting The Login Functionality.

Original Request

alt text

Steps

Exploited Request

alt text

My Info

Yeswehack  : https://yeswehack.com/hunters/mekky

Intigriti  : https://app.intigriti.com/researcher/profile/mekky

Linkedin   : https://www.linkedin.com/in/muhammed-mekkawy-1504821b2/

Twitter    : https://twitter.com/Mekky49295157