Email Verification Bypass
Last updated
Last updated
Intercept change email request and send it to repeater
Send the request at least 2 times so send it to the repeater again
Repeater 1
Repeater 2
Create group to be able to send the two requests in the same time
Send group in parallel
Modify the email
parameter from attacker@gmail.com
to a different email address (for this example, victim@gmail.com)
Intercept the request
Remove the token
Change STATUS to “VERIFIED,” refresh the page, and gain access to the solutions without verifying the address