{"id":2591,"date":"2019-08-17T03:04:08","date_gmt":"2019-08-16T21:34:08","guid":{"rendered":"https:\/\/ninadmathpati.com\/?p=2591"},"modified":"2020-09-13T06:39:21","modified_gmt":"2020-09-13T06:39:21","slug":"how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty","status":"publish","type":"post","link":"https:\/\/ninadmathpati.com\/hi\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/","title":{"rendered":"How I was able to earn 1000$ with just 10 minutes of bug bounty?"},"content":{"rendered":"<p class=\"has-medium-font-size\">Hello, Guys, I m back with a new blog on bug bounty, I found this bug recently on independent bug bounty program, thought of sharing it.<\/p>\n\n\n\n<p class=\"has-medium-font-size\">So here I would like to share how I got 1000$ with just 10 minutes of bug hunting,<\/p>\n\n\n\n<p class=\"has-medium-font-size\">here you will get to know the importance of <strong><em>client-side vulnerabilities<\/em><\/strong>,<\/p>\n\n\n\n<p class=\"has-medium-font-size\">So here&#8217;s how it went on, earlier during my engineering 4th year, I had too much free time. This was the time I learnt a lot about this field,  That time my daily schedule was like,  <\/p>\n\n\n\n<p class=\"has-very-light-gray-background-color has-background has-huge-font-size\"><strong><em>Eat-&gt; Sleep -&gt; Bug Hunting -&gt; Repeat<\/em><\/strong><\/p>\n\n\n\n<p class=\"has-medium-font-size\">A few months back, I thought to let&#8217;s give it a try so I just picked a random website lets to say <strong><em>asdf.com<\/em><\/strong><\/p>\n\n\n\n<p class=\"has-medium-font-size\">Now, asdf.com is a cryptocurrency exchange website, and in a general way I tried to scan the website while doing the testing I came across the login page and got to know that we can create an account and so after creating the account I found out a place where we could request for password reset for our account. On the login page there was an option of reset password so just to give it a check I requested for my password reset through that reset option, The forgot password link was something like this, <\/p>\n\n\n\n<pre class=\"wp-block-preformatted\" style=\"font-size: 20px;\"><strong><em>www.asdf.com\/resetpsswd\/email=hacker2202@asdf.com&amp;token=aknajdnskvbskfv34tr34nj3rrff33grjqw<\/em><\/strong><\/pre>\n\n\n\n<p class=\"has-medium-font-size\">Here if you notice, there&#8217;s and email change option. I tried changing the email address and checking the link and what a stroke of luck it was just 5 minutes of testing I got the bug, but after changing the email I was not able to change the password as the site has 2-factor authentication implemented.<\/p>\n\n\n\n<p class=\"has-medium-font-size\">As the 2-factor authentication was implemented I thought we cannot do anything of it now as altering the email doesn&#8217;t work, but suddenly I saw a mail-in my altered email inbox it was from the asdf.com it was like,<\/p>\n\n\n\n<p class=\"has-medium-font-size\">I got a new reset password link of that account to my altered email address.<\/p>\n\n\n\n<p class=\"has-medium-font-size\">So what was happening was <\/p>\n\n\n\n<p class=\"has-medium-font-size\">when we are requesting a password reset for our account we were getting a mail and that reset password link had token expiration vulnerability ( it was not expiring the token after one use)<\/p>\n\n\n\n<p class=\"has-medium-font-size\">2nd the problem was when I was altering the email  and processing the link I was able to get a new reset link to my altered email address of the victim&#8217;s account (not exactly same but something like Http pollution attack)<\/p>\n\n\n\n<figure class=\"wp-block-gallery columns-1 is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\"><ul class=\"blocks-gallery-grid\"><li class=\"blocks-gallery-item\"><figure><img decoding=\"async\" loading=\"lazy\" width=\"708\" height=\"134\" src=\"https:\/\/ninadmathpati.com\/wp-content\/uploads\/2020\/09\/1000.png\" alt=\"\" data-id=\"4691\" data-full-url=\"https:\/\/ninadmathpati.com\/wp-content\/uploads\/2020\/09\/1000.png\" data-link=\"https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/attachment\/1000\/\" class=\"wp-image-4691\" srcset=\"https:\/\/ninadmathpati.com\/wp-content\/uploads\/2020\/09\/1000.png 708w, https:\/\/ninadmathpati.com\/wp-content\/uploads\/2020\/09\/1000-300x57.png 300w\" sizes=\"(max-width: 708px) 100vw, 708px\" \/><\/figure><\/li><\/ul><\/figure>\n\n\n\n<p class=\"has-medium-font-size\">So in this way, I was able to earn good, client-side attacks also pay very well if we show the <strong><em>attack scenario properly<\/em><\/strong>.<\/p>\n\n\n\n<p class=\"has-medium-font-size\">What might be the fix for this type of issues?<\/p>\n\n\n\n<ul style=\"font-size: 20px;\"><li><em>Token Verification &amp; Expiration.<\/em><\/li><li><em>Avoiding unnecessary Parameters Like Email<\/em><\/li><li><em>Implementation of 2 Factor-Authentication.<\/em><\/li><li><em>Most importantly checking the workflow of that section <\/em><\/li><\/ul>\n\n\n\n<p class=\"has-medium-font-size\">This was just an example for client-side attack I will be discussing in detail about client-side attacks in my further blogs (Will publish it soon)<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-style-large\"><p>&#8220;So Next time you see any parameter try to play with it who knows you might get lucky and get some bucks added to your account&#8221;<\/p><\/blockquote>\n\n\n\n<p class=\"has-medium-font-size\">This blog I have only made for the specific findings only,  Do Subscribe to my blog if you find it useful!!!<\/p>\n\n\n\n<p class=\"has-medium-font-size\"><strong><em>Hint for the next blog:<\/em><\/strong> Is it possible to hijack a browser through XSS?<\/p>","protected":false},"excerpt":{"rendered":"<p>Hello, Guys, I m back with a new blog on bug bounty, I found this bug recently on independent bug bounty program, thought of sharing it. So here I would like to share how I got 1000$ with just 10 minutes of bug hunting, here you will get to know the importance of client-side vulnerabilities,&#8230;<\/p>\n<p><a class=\"read-more\" href=\"https:\/\/ninadmathpati.com\/hi\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/\">Read More<\/a><\/p>","protected":false},"author":1,"featured_media":4387,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_mi_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[34],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v21.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How I was able to earn 1000$ with just 10 minutes of bug bounty? - Ninad Mathpati<\/title>\n<meta name=\"description\" content=\"All about Password reset configurations\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/ninadmathpati.com\/hi\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/\" \/>\n<meta property=\"og:locale\" content=\"hi_IN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How I was able to earn 1000$ with just 10 minutes of bug bounty? - Ninad Mathpati\" \/>\n<meta property=\"og:description\" content=\"All about Password reset configurations\" \/>\n<meta property=\"og:url\" content=\"https:\/\/ninadmathpati.com\/hi\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/\" \/>\n<meta property=\"og:site_name\" content=\"Ninad Mathpati\" \/>\n<meta property=\"article:published_time\" content=\"2019-08-16T21:34:08+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-09-13T06:39:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/ninadmathpati.com\/wp-content\/uploads\/2019\/08\/client-side-attacks-768x404-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"768\" \/>\n\t<meta property=\"og:image:height\" content=\"404\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ninad Mathpati\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@ninad_mathpati\" \/>\n<meta name=\"twitter:site\" content=\"@ninad_mathpati\" \/>\n<meta name=\"twitter:label1\" content=\"\u0926\u094d\u0935\u093e\u0930\u093e \u0932\u093f\u0916\u093f\u0924\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ninad Mathpati\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u0905\u0928\u0941\u092e\u093e\u0928\u093f\u0924 \u092a\u0922\u093c\u0928\u0947 \u0915\u093e \u0938\u092e\u092f\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 \u092e\u093f\u0928\u091f\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/\"},\"author\":{\"name\":\"Ninad Mathpati\",\"@id\":\"https:\/\/ninadmathpati.com\/#\/schema\/person\/f19cd13cb1ebac284a486cd18056766a\"},\"headline\":\"How I was able to earn 1000$ with just 10 minutes of bug bounty?\",\"datePublished\":\"2019-08-16T21:34:08+00:00\",\"dateModified\":\"2020-09-13T06:39:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/\"},\"wordCount\":570,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\/\/ninadmathpati.com\/#\/schema\/person\/f19cd13cb1ebac284a486cd18056766a\"},\"articleSection\":[\"Bug Bounty\"],\"inLanguage\":\"hi-IN\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/\",\"url\":\"https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/\",\"name\":\"How I was able to earn 1000$ with just 10 minutes of bug bounty? - Ninad Mathpati\",\"isPartOf\":{\"@id\":\"https:\/\/ninadmathpati.com\/#website\"},\"datePublished\":\"2019-08-16T21:34:08+00:00\",\"dateModified\":\"2020-09-13T06:39:21+00:00\",\"description\":\"All about Password reset configurations\",\"inLanguage\":\"hi-IN\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/ninadmathpati.com\/#website\",\"url\":\"https:\/\/ninadmathpati.com\/\",\"name\":\"Ninad Mathpati\",\"description\":\"Security Consultant\",\"publisher\":{\"@id\":\"https:\/\/ninadmathpati.com\/#\/schema\/person\/f19cd13cb1ebac284a486cd18056766a\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/ninadmathpati.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"hi-IN\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/ninadmathpati.com\/#\/schema\/person\/f19cd13cb1ebac284a486cd18056766a\",\"name\":\"Ninad Mathpati\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"hi-IN\",\"@id\":\"https:\/\/ninadmathpati.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/ninadmathpati.com\/wp-content\/uploads\/2020\/07\/IMG-1632123.jpg\",\"contentUrl\":\"https:\/\/ninadmathpati.com\/wp-content\/uploads\/2020\/07\/IMG-1632123.jpg\",\"width\":851,\"height\":1093,\"caption\":\"Ninad Mathpati\"},\"logo\":{\"@id\":\"https:\/\/ninadmathpati.com\/#\/schema\/person\/image\/\"},\"sameAs\":[\"https:\/\/ninadmathpati.com\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How I was able to earn 1000$ with just 10 minutes of bug bounty? - Ninad Mathpati","description":"All about Password reset configurations","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/ninadmathpati.com\/hi\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/","og_locale":"hi_IN","og_type":"article","og_title":"How I was able to earn 1000$ with just 10 minutes of bug bounty? - Ninad Mathpati","og_description":"All about Password reset configurations","og_url":"https:\/\/ninadmathpati.com\/hi\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/","og_site_name":"Ninad Mathpati","article_published_time":"2019-08-16T21:34:08+00:00","article_modified_time":"2020-09-13T06:39:21+00:00","og_image":[{"width":768,"height":404,"url":"https:\/\/ninadmathpati.com\/wp-content\/uploads\/2019\/08\/client-side-attacks-768x404-1.jpg","type":"image\/jpeg"}],"author":"Ninad Mathpati","twitter_card":"summary_large_image","twitter_creator":"@ninad_mathpati","twitter_site":"@ninad_mathpati","twitter_misc":{"\u0926\u094d\u0935\u093e\u0930\u093e \u0932\u093f\u0916\u093f\u0924":"Ninad Mathpati","\u0905\u0928\u0941\u092e\u093e\u0928\u093f\u0924 \u092a\u0922\u093c\u0928\u0947 \u0915\u093e \u0938\u092e\u092f":"3 \u092e\u093f\u0928\u091f"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/#article","isPartOf":{"@id":"https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/"},"author":{"name":"Ninad Mathpati","@id":"https:\/\/ninadmathpati.com\/#\/schema\/person\/f19cd13cb1ebac284a486cd18056766a"},"headline":"How I was able to earn 1000$ with just 10 minutes of bug bounty?","datePublished":"2019-08-16T21:34:08+00:00","dateModified":"2020-09-13T06:39:21+00:00","mainEntityOfPage":{"@id":"https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/"},"wordCount":570,"commentCount":1,"publisher":{"@id":"https:\/\/ninadmathpati.com\/#\/schema\/person\/f19cd13cb1ebac284a486cd18056766a"},"articleSection":["Bug Bounty"],"inLanguage":"hi-IN","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/","url":"https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/","name":"How I was able to earn 1000$ with just 10 minutes of bug bounty? - Ninad Mathpati","isPartOf":{"@id":"https:\/\/ninadmathpati.com\/#website"},"datePublished":"2019-08-16T21:34:08+00:00","dateModified":"2020-09-13T06:39:21+00:00","description":"All about Password reset configurations","inLanguage":"hi-IN","potentialAction":[{"@type":"ReadAction","target":["https:\/\/ninadmathpati.com\/2019\/08\/17\/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty\/"]}]},{"@type":"WebSite","@id":"https:\/\/ninadmathpati.com\/#website","url":"https:\/\/ninadmathpati.com\/","name":"Ninad Mathpati","description":"Security Consultant","publisher":{"@id":"https:\/\/ninadmathpati.com\/#\/schema\/person\/f19cd13cb1ebac284a486cd18056766a"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ninadmathpati.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"hi-IN"},{"@type":["Person","Organization"],"@id":"https:\/\/ninadmathpati.com\/#\/schema\/person\/f19cd13cb1ebac284a486cd18056766a","name":"Ninad Mathpati","image":{"@type":"ImageObject","inLanguage":"hi-IN","@id":"https:\/\/ninadmathpati.com\/#\/schema\/person\/image\/","url":"https:\/\/ninadmathpati.com\/wp-content\/uploads\/2020\/07\/IMG-1632123.jpg","contentUrl":"https:\/\/ninadmathpati.com\/wp-content\/uploads\/2020\/07\/IMG-1632123.jpg","width":851,"height":1093,"caption":"Ninad Mathpati"},"logo":{"@id":"https:\/\/ninadmathpati.com\/#\/schema\/person\/image\/"},"sameAs":["https:\/\/ninadmathpati.com"]}]}},"_links":{"self":[{"href":"https:\/\/ninadmathpati.com\/hi\/wp-json\/wp\/v2\/posts\/2591"}],"collection":[{"href":"https:\/\/ninadmathpati.com\/hi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ninadmathpati.com\/hi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ninadmathpati.com\/hi\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ninadmathpati.com\/hi\/wp-json\/wp\/v2\/comments?post=2591"}],"version-history":[{"count":3,"href":"https:\/\/ninadmathpati.com\/hi\/wp-json\/wp\/v2\/posts\/2591\/revisions"}],"predecessor-version":[{"id":4693,"href":"https:\/\/ninadmathpati.com\/hi\/wp-json\/wp\/v2\/posts\/2591\/revisions\/4693"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ninadmathpati.com\/hi\/wp-json\/wp\/v2\/media\/4387"}],"wp:attachment":[{"href":"https:\/\/ninadmathpati.com\/hi\/wp-json\/wp\/v2\/media?parent=2591"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ninadmathpati.com\/hi\/wp-json\/wp\/v2\/categories?post=2591"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ninadmathpati.com\/hi\/wp-json\/wp\/v2\/tags?post=2591"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}