Posts

Showing posts from September, 2017

Two Factor Authentication Bypass | SendGrid

Image
Hello All, Today I will be sharing how I was able to Bypass SendGrid 2FA What is SendGrid : A Cloud-based email service to  deliver emails on behalf of companies having  55,000+ customers ~ https://sendgrid.com/about/ What is Two  Factor Authentication : Two-Factor Authentication (2FA) is a type of multi-factor authentication confirming a user’s claimed identity by utilizing a combination of two different authentication methods. 2FA makes it harder for potential intruders to gain access and steal user’s personal data or identity. ~ https://en.wikipedia.org/wiki/Multi-factor_authentication My Story with them : I started looking for bugs in SendGrid  and after trying whole night i found  a  XSS Reported it and when to sleep peacefully Next morning I checked my email The bug went duplicate :(  It felt bad I didn't want to test further so I went to delete my account ( I don't want emails from them :__: ) I logged in to my account to see i