This is part 5 of P4 bug’s if you haven’t check previous part then check it out. Part 1 , Part 2, Part 3, Part 4

Hi everyone, I am socalledhacker, i am a security researcher , penetration tester, certified ethical hacker and a web3 noob. In past months, I have discover lots of bugs but in today’s article we are going to discuss about low hanging fruits or P4 vuln’s as they are very easy to find and also present in almost every website. So let’s start with our first vulnerability.
1. Delete Account Without Password
This bug is very easy as we can understand it by it’s name. So, when we delete our account form a website and it asks password of the account but in some website when we click on delete account, our account is directly deleted without password then it is considered as a bug.
Now, I think you found this bug so time to create it’s report…
Description:- The removal of an account is one of the sensitive parts of a web application that needs to protect, therefore deleting an account should validate the authenticity of the user.
Steps to reproduce:-
- Visit the website and login into your account.
- Go to the profile/settings section.
- A delete account button will be displayed.
- Click on delete button and your account is successfully deleted.
Impact:-
The target doesn’t verify the request with a Valid OTP or password before triggering Right to Access/Deletion & allows an attacker to delete User Accounts without user interaction.
2. SPF and DMARC Record
Don’t you dare to ask me what is SPF and DMARC record is you can easily found this on google or on other articles.
So, let’s talk about the bug here, we usually found company email on their website and if the SPF and DMARC record is not published for their mail id then it’s vulnerable to email spoofing attacks.
How to check if SPF and DMARC record is published or not? Check it here
SPF record — https://www.kitterman.com/spf/validate.html
DMARC record — https://mxtoolbox.com/
Criteria: These bugs may be out of scope on platform so read full scope before submitting.
Time to create report….
For SPF….
Description:- The Sender Policy Framework (SPF) is an email authentication protocol and part of email cybersecurity used to stop phishing attacks.
Steps to reproduce:-
- Visit — https://www.kitterman.com/spf/validate.html
- Enter the domain name — target.com and hit get SPF Record
- The domain name will show No valid SPF record found
Impact:-
Spammers can forge the “From” address on email messages to make messages appear to come from someone in your domain. If spammers use your domain to send spam or junk email, your domain quality is negatively affected. People who get the forged emails can mark them as spam or junk, which can impact authentic messages sent from your domain.
For DMARC…
Description:- DMARC (Domain-based Message Authentication, Reporting, and Conformance) is an email authentication protocol. It is designed to give email domain owners the ability to protect their domain from unauthorized use, commonly known as email spoofing.
Steps to reproduce:-
- Visit — https://mxtoolbox.com
- Enter the domain name — target.com and hit go
- The domain name will show No DMARC Record found
Impact:-
Spammers can forge the “From” address on email messages to make messages appear to come from someone in your domain. If spammers use your domain to send spam or junk email, your domain quality is negatively affected. People who get the forged emails can mark them as spam or junk, which can impact authentic messages sent from your domain.
That’s it for this article I will upload more articles related to web2 bugs covering all p4 to p1 bugs in near future so stay tuned … 🙂
Buy Me a Coffee : https://buymeacoffee.com/socalledhacker
Follow Me On :
Thank you for being of assistance to me. I really loved this article.
With havin so much content and articles do you ever run into any issues of plagorism or copyright violation? My site has a lot of exclusive content I’ve either created myself or outsourced but it looks like a lot of it is popping it up all over the web without my agreement. Do you know any methods to help protect against content from being ripped off? I’d definitely appreciate it.
Wonderful beat ! I would like to apprentice while you amend your website, how can i subscribe for a weblog website? The account helped me a applicable deal. I were a little bit familiar of this your broadcast offered brilliant clear idea
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
This is a great article!
Do you have plans to create a comprehensive course on this topic?
The case studies really drove your points home. Very convincing!
Any chance you could elaborate more on the third point? Still a bit confused there.
Reading your blog has become part of my morning routine. Always insightful.
How do you consistently produce such high-quality content? Always impressed.
A leading spine neurosurgeon is being called out for a video that shows him pulling off a female MP’s election sign and throwing it into a dumpster while telling viewers how to ‘bury the body’.
This is a great article!
We are a group of volunteers and starting a new scheme in our community. Your website provided us with valuable info to work on. You have done a formidable job and our whole community will be thankful to you.
This is a great article!
hey there!
hey there!
hey there!
hey there!
hey there!
hika ah thil pakhatkhat a cang khomi a um maw ka ngandamnak caah zeidah a tuah?
hika ah thil pakhatkhat a cang khomi a um maw ka ngandamnak caah zeidah a tuah?
retail business signs
Betty roof repair lutz
great post!
great post!
great post!
this is a great post!
this is a great post!
this is a great post!
this is a great post!
this is a great post!
this is a great post!
Эта публикация дает возможность задействовать различные источники информации и представить их в удобной форме. Читатели смогут быстро найти нужные данные и получить ответы на интересующие их вопросы. Мы стремимся к четкости и доступности материала для всех!
Получить дополнительные сведения – https://medalkoblog.ru/
Well done.
Great job on this.
Food for thought, indeed.
this is a great post!
this is a great post!
this is a great post!
this is a great post!
this is a great post!