Summary:
No rate limit in send verification code to Email
Steps To Reproduce:
- Create an account and login https://dashboard.example.io/signin then ask verification code to mail.
- Click resend code and capture the request in burpsuite.
- move the request to Intruder and go to position and clear and put payload type "Null payloads" and generate "100" payloads and click start attack.
- Boom 100 verification recieve my Email.
Impact
Attacker can bomb victim mobile inbox and cause MTN to loose the charges of sms in vein.
Post a Comment