Resources

People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!

Tiki Wiki CMS Authentication Bypass- 300

Maximilian BarzPosted 5 Years Ago
  • Brute force protections gone wrong! After 20 failed login attempts, an email attempts to be sent to the user/admin.
  • After 50 attempts, the password is cleared in order to indicate that the password should be reset. But, by sending a blank password, it will login the user!
  • This is a ridiculous auth bypass but is super interesting!