Security vulnerabilities

  • Status Closed
  • Assigned To
    nferrari
  • Private
Attached to Project: Security vulnerabilities
Opened by monty099 - 26.08.2024
Last edited by nferrari - 28.08.2024

FS#72 - **Security Report: Disclosure of Two-Factor Authentication Status** in [admin.alwaysdata.com]

Security Report: Disclosure of Two-Factor Authentication Status in [admin.alwaysdata.com]

Summary:

A vulnerability exists where the two-factor authentication (2FA) status of a user account can be determined by adding the user as an administrator to your account. This issue exposes whether the user has 2FA enabled or not.

Steps to Reproduce:

1. Attempt to Log In with Incorrect Credentials:

  1. Start by trying to log in with incorrect credentials. This demonstrates that you cannot determine whether 2FA is enabled based on the failed login attempt alone.

2. Observe the Failed Login Behavior:

  1. Note that with incorrect login credentials, it is not possible to ascertain the 2FA status of the user account.

3.You can't know that the account has activated two-factor authentication until you provide the correct credentials and then it will transfer you to the next stage where you will be asked for the two-factor authentication number

4. Add the User as an Administrator:

  1. Add the user in question as an administrator to your account.
  2. Upon doing so, you will be able to see whether this user has 2FA enabled or not.

I sent a proof of concept:https://admin.alwaysdata.com/support/77431/377370-bandicam%202024-08-26%2019-23-18-853.mp4

Impact:

The ability to determine the 2FA status of a user account can pose a security risk. Attackers who gain administrative access could potentially use this information to tailor their attacks based on whether a target user has an additional layer of security.

Closed by  nferrari
28.08.2024 08:01
Reason for closing:  Invalid
Admin

Hi,

Thank you for your report.

Can you please open a dedicated ticket on our support system, with appropriate title so we can link it to this report and find your POC?

We will look at it shortly and come back to you.

Regards,

Admin

Hi,

This behavior is normal since it comes from a decision made by design. There is no real security risk, every user can still configure 2FA on their profile.

Regards,

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing