Jump to content
QuoVadis

PayPal 2FA Bypass

Recommended Posts

Posted

Recently I was in a hotel needing to make a payment, there was no phone signal so I could not receive my Two Factor Auth token. Luckily for me Paypal’s 2FA took less than five minutes to bypass.

 

Proof of Concept
Step 1: Login with a valid username and password, click on the “Try another way” link.

 

verifynumber.png

 

Step 2: Enter any answer for security questions.

 

securityquestions.png

 

Step 3: Using a proxy, remove “securityQuestion0” and “securityQuestion1” from the post data.

 

postdata.png

 

Step 4: Profit

 

verified.png

 

Advisory Timeline
03/10/16 - Reported issue to Paypal
04/10/16 - Paypal begin investigation of issue
21/10/16 - Paypal report issue as fixed
21/10/16 - Paypal award bounty

 

https://henryhoggard.co.uk/blog/Paypal-2FA-Bypass

  • Upvote 2

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...