Bypassing Authentication Using Javascript Debugger.

So I  was checking a website and tried to test it for flaws just a general thing nothing new. I targeted the login mechanism. I saw while clicking on it. It was generating javascript events.

Screen Shot 2018-09-18 at 3.47.17 PM

 

Screen Shot 2018-09-18 at 3.49.12 PM

so the hunt began for this function. i saw every .js files . you know where I found it js//facebook.js lol

Screen Shot 2018-09-18 at 4.02.18 PM

 

Screen Shot 2018-09-18 at 4.02.38 PM

Here is the function related to authentication ……

Screen Shot 2018-09-18 at 4.02.52 PM

Putting a breakpoint on data variable comparison.

Screen Shot 2018-09-18 at 4.04.16 PM

Screen Shot 2018-09-18 at 4.04.46 PM

Screen Shot 2018-09-18 at 4.04.59 PM

Modifying the data value in the console.

Screen Shot 2018-09-18 at 4.05.15 PM

Screen Shot 2018-09-18 at 4.05.32 PM

Screen Shot 2018-09-18 at 4.06.09 PM

Voila, more information!!!!!!!

Screen Shot 2018-09-18 at 4.19.19 PM

Screen Shot 2018-09-18 at 4.19.32 PM.png

 

 

4 thoughts on “Bypassing Authentication Using Javascript Debugger.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s