2FA
1. 2FA Setup
1. Login to the application 2. Setup two factor authentication 3. After the 2FA secret is created, observe that there is no way in which the secret can be rotated - <https://bugcrowd.com/disclosures/0c8a87aa-f10f-4174-b6d8-56c365062910/2fa-secret-is-not-rotated> - <https://zofixer.com/what-is-weak-2fa-implementation-2fa-secret-cannot-be-rotated-vulnerability/>
If Target allows using 2FA authenticator like google authenticator or Microsoft authenticator etc... Try to Find a path that leaks QR code Or the secret that shows when enable the 2fa authentication Analyze JS Files and try to understand how the target generate the secret test if the 2FA secret is still retrievable even after the 2FA feature has been activated by Replay Attacks or something - <https://bugcrowd.com/vulnerability-rating-taxonomy> - <https://github.com/bugcrowd/vulnerability-rating-taxonomy/issues/203>
2. 2FA Bypass
3. Disable 2FA
Last updated