Session Based Bugs

Old Session Does Not Expire After Password Change:

  • Steps:

      1.create An account On Your Target Site
      2.Login Into Two Browser With Same Account(Chrome, FireFox.You Can Use Incognito Mode As well) 
      3.Change You Password In Chrome, On Seccessfull Password Change Referesh Your Logged in Account In FireFox/Incognito Mode.
      4.If you'r still logged in Then This Is a Bug

Session Hijacking (Intended Behavior)

  • Steps:

    1.Create your account
    2.Login your account
    3.Use cookie editor extension in browser
    4.Copy all the target cookies
    5.Logout your account
    6.Paste that cookies in cookie editor extension
    7.Refresh page if you are logged in than this is a session hijacking

Impact: If attacker get cookies of victim it will leads to account takeover.

Password reset token does not expire (Insecure Configurability)

  • Steps:

Server security misconfiguration -> Lack of security headers -> Cache control for a security page

  • Steps :

Impact: At a PC cafe, if a person was in a very important page with alot of details and logged out, then another person comes and clicks back (because he didnt close the browser) then data is exposed. User information leaked

Broken Authentication To Email Verification Bypass (P4) :

category : P4 >> Broken Authentication and Session Management >> Failure to Invalidate Session >> On Password Reset and/or Change

  • Steps To Reproduce:

Impact : Email Verfication was bypassed due to Broken Authentication Mechanism , Thus more Privileged account can be accessed by an attacker making website prone to Future Attacks. Happy Hacking:)

Email Verification Bypass (P3/P4)

  • Steps :

Impact : Email Verfication Bypass

Old Password Reset Token Not Expiring Upon Requesting New One (Sometimes P4) :

  • Steps :

  • Note:- Some Companies Won't Accept it As Valid Issue.

Password Reset Token Not Expiring After Password Change (P4):

  • Steps :

Insufficient account process validation leads to account takeover (P3/P4):

  • Steps :

  • Thanks For Reading Guys Happy Hunting :).

    Resources:

    Google,Youtube.

Authors

Last updated