Это видео недоступно.
Сожалеем об этом.

$37,500 Shopify auth bypass - Hackerone

Поделиться
HTML-код
  • Опубликовано: 18 авг 2024
  • 📧 Subscribe to BBRE Premium: bbre.dev/premium
    ✉️ Sign up for the mailing list: bbre.dev/nl
    📣 Follow me on Twitter: bbre.dev/tw
    This time I have for you more than one bug bounty report. It's three reports in total but all of them affect the same functionality and are tightly correlated. They led to the auth bypass and account takeovers on Shopify and exploited email confirmation flow.
    Report links:
    hackerone.com/...
    hackerone.com/...
    hackerone.com/...
    Hacker:
    hackerone.com/...
    / ngalongc
    Reconless channel:
    / @reconless
    Follow me on twitter:
    / gregxsunday
    Timestamps:
    00:00 Intro
    00:33 verifying someone's email address
    01:28 exploiting email confirmation vulnerability
    02:06 first fix
    03:50 limited impact and third report
    05:20 escalating the impact
    #auth #bypass #shopify #hackerone #ato #account #takeover

Комментарии • 54

  • @BugBountyReportsExplained
    @BugBountyReportsExplained  3 года назад +3

    Welcome to the comment section!
    First, thanks for watching!
    Make sure you are subscribed if you liked the video!
    ruclips.net/user/BugBountyReportsExplained
    Follow me on twitter:
    twitter.com/gregxsunday
    ✉️ Sign up for the mailing list ✉️
    mailing.bugbountyexplained.com/
    ☕️ Support my channel ☕️
    www.buymeacoffee.com/bountyexplained
    🖥 Get $100 in credits for Digital Ocean 🖥
    m.do.co/c/cc700f81d215

    • @watchlistsclips3196
      @watchlistsclips3196 3 года назад

      @Kristian Ian Hello scammer how are you doing

    • @watchlistsclips3196
      @watchlistsclips3196 3 года назад

      @Kristian IanI don't know if anyone cares this is a scam.Took me just 3 sec to find it out.

  • @CommitSNIPS
    @CommitSNIPS 4 года назад +27

    Love this format of content! I can tell you put a lot of effort into this

  • @firewallguy
    @firewallguy 3 года назад +5

    Your videos are simple to understand and awesome.

  • @rodrigomolinagarrido
    @rodrigomolinagarrido 3 года назад +1

    subscribed after just watching two vids, amazing content

  • @avisawade6190
    @avisawade6190 3 года назад +3

    Awesome Explanation Buddy

  • @ElektroDrrrEL
    @ElektroDrrrEL 3 года назад +5

    content is perfect - thank you!

  • @_rudra_raj_4844
    @_rudra_raj_4844 4 года назад +5

    Please make more such vedios ... It's really helpful ... Thanks

  • @steiner254
    @steiner254 Год назад +1

    Great explanation bro

  • @LOL-qj4kw
    @LOL-qj4kw 3 года назад +3

    That was really generous of shoppify team to reward bounty twice..... While on the other hand there have been many cases from multiple different programs where the vulnerability was patched and hacker wasnt even rewarded once

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  3 года назад +5

      I havent hacked on them, but by looking at their reports, they seem really fair with hunters - always responding, explaining the bounty etc.

  • @bughunter1731
    @bughunter1731 3 года назад

    Nice contents sir! Already subscribed. Hoping that you upload more videos🥳

  • @_____m________6684
    @_____m________6684 4 года назад +4

    hey man! Thanks for this information.. keep it up i'm your new subscriber :)

  • @anakinskywalkerrr
    @anakinskywalkerrr 4 года назад +1

    ngalog is a down to earth beast

  • @gustialfian
    @gustialfian 4 года назад +2

    This is crazy🔥 i was looking for bug on account 2fa system at shopify but didn't got anything

  • @trieulieuf9
    @trieulieuf9 4 года назад +1

    Ngalog is a beast.

  • @mohits8021
    @mohits8021 3 года назад +2

    Hi, I have a few questions, I would be grateful if anyone could answer my queries
    1) How would the hacker know about the new accounts which have not been confirmed? I am assuming that the confirmation is for new accounts , not for old ones correct me if I am wrong.
    2) How did the hacker got to know about the merge accounts path/url?
    3) Can't shopify disable/remove the change email id link while confirmating an account?

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  3 года назад +2

      Ad 1 The hacker would create a new account with his new email and then change his email to victim's email. The attacker does not need to find unconfirmed accounts.
      Ad 2 he has probably gone through the whole process of merging accounts multiple times on accounts that he controls. So he knew what happens when and when what link is used
      Ad 3 They probably could, but it's possible to fix it other way

    • @mohits8021
      @mohits8021 3 года назад

      @@BugBountyReportsExplained Thanks for the reply. I have one more query. Isn't the confirmation thing for the new accounts only as confirmation happens only when the account is new but not for old accounts?

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  3 года назад +1

      Thanks for the question. Yes, confirmation is for new accounts only, so the attacker needs to create a new account for each victim.

    • @mohits8021
      @mohits8021 3 года назад

      @@BugBountyReportsExplained Thanks a lot.

  • @tigerarabia383
    @tigerarabia383 3 года назад

    New sub here, really amazing content. I love your videos❤️

  • @OthmanAlikhan
    @OthmanAlikhan Год назад

    Thanks for the video =)

  • @rhyswoolcott
    @rhyswoolcott 3 года назад +1

    This guy looks like every teenage bully in cartoons

  • @meetsodha1244
    @meetsodha1244 4 года назад +1

    Thanks for sharing

  • @carljustinemosquida9614
    @carljustinemosquida9614 3 года назад +2

    New sub here , please do create more vids like this😎

  • @meetsodha1244
    @meetsodha1244 4 года назад

    But what we will do if the program says how will you get access to the attackers account for changing email address

  • @melvin16
    @melvin16 3 года назад

    Superb. Please make more videos 👍👌

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  3 года назад +1

      Im happy you like them, but I put a lot of time into each video and making more might affect quality.

  • @nillagra9343
    @nillagra9343 2 года назад

    For Hindi....?

  • @viktorsamo5500
    @viktorsamo5500 3 года назад

    Wtf? 2500+5000+7500=37500 ???

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  3 года назад +3

      your maths is a little bit off :/

    • @viktorsamo5500
      @viktorsamo5500 3 года назад

      @@BugBountyReportsExplained in video i see payment 2500 not 25k, 2500+5000+7500?

    • @gabe8168
      @gabe8168 3 года назад +4

      @@viktorsamo5500 15k + 15k + 7.5k = 37.5k. The math isn't that hard. Did you only watch the end of the video? You obviously didn't watch the whole thing

  • @hamza6869
    @hamza6869 4 года назад

    ❤️

  • @andrejprenkelushaj9578
    @andrejprenkelushaj9578 3 года назад

    😕😟