OTP lockout state leaked valid-code signal, enabling OLX account takeover
I published a technical write-up on an old OLX account takeover issue. The core bug was an OTP correctness leak inside the rate-limit state. After repeated invalid OTP attempts, the application showed a lockout message.
📄
This source provides headlines only. Use the button below to read the complete article on the original site.
📰 Read the original article on r/netsec
Originally published by r/netsec. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.