Sinisterly
Tutorial | CAB - Custom Authorization Bypass - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.li/Forum-Tutorials)
+--- Thread: Tutorial | CAB - Custom Authorization Bypass (/Thread-Tutorial-CAB-Custom-Authorization-Bypass)



Tutorial | CAB - Custom Authorization Bypass - Xcel3rated 360 - 10-13-2013

CAB - Custom Authorization Bypass

[b]Custom Authorization : the type of authorization which involves a User and Password Which Results in a String of Code sent to The server for verification .


String :

PHP Code:
Code:
www.x.com/Login.php?id=adam+pwd=123

Now it gives a error that password is not Correct

We know that the adam's profile link is :

PHP Code:
Code:
www.x.com/profile.php?id=9813

now edit the String to :
PHP Code:
Code:
www.x.com/Login.php?id=adam+pwd=(fromDB9.8{y}1.3{z})

now , in the above String we are representing the DB map in coordinate system .

Now it will bypass The login medium and the Login will be cleared out !


RE: Tutorial | CAB - Custom Authorization Bypass - XWorm - 11-16-2013

Interesting authentication.. First time I see it :S