CyberWiseCon Europe 2025

Muhammad Shahmeer: The Art of Cyber Espionage: Unleashing the Power of SCADA and ICS Hacking

45:55 · 20 May 2025 – 23 May 2025 · YouTube

About this talk

This talk focuses on bypassing next-generation two-factor authentication (TFA) and multi-factor authentication (MFA) implementations. The speaker, Shamir Amir, who is recognized as a leading bug bounty hunter, elaborates on the evolution of TFA and MFA, and discusses their vulnerabilities. He explains various methods to bypass these security measures, highlighting issues such as brute force attacks, broken session management, and code reusability flaws through detailed case studies involving platforms like Microsoft, Slack, and Grab. The talk also touches on advanced bypass techniques, including manipulation of request and response parameters, as well as the risks associated with legacy protocols and social login integrations. Overall, the session aims to raise awareness about the security implications of relying solely on TFA and MFA mechanisms.

Full transcript

[Music] hello everyone again uh we are reaching approaching the end of the uh the day for the devops pro I say a couple of minutes ago that in 10 minutes we will be back it was sooner I was having some issues with the schedule today honestly between the time zone change and everything it's a little bit complicated for me anyways probably I need some coffee eventually um

next session uh we are going to be with Shamir Amir apologies again I'm usually pronounce it in a very bad way so apologize for that um he's a well world-renown uh ethical hacker and he accomp it's the third most accomplished bu Hunter so be careful with him because if you doing some back he can probably hunt it and Chase it and completely squash it um he's the

CEO of junit um so welcome Shakir on stage apologies again if I'm pronouncing your name uh in a wrong way uh thank you thank you so much uh it's it's it's a pleasure to be here and uh I hope that I don't disappoint the audience with the amazing introduction that you just gave well I put the the bar a little bit high right it's a little bit

High anyway exactly exactly I'm hoping not to disappoint that's basically it yeah we we are not going to talk about bug hunting but I'm going to leave you uh the stage for you and so you can start the uh presentation uh whenever you want okay okay hello everyone uh uh first of all uh welcome you all to this amazing session this amazing talk that we're going to

have today uh it's about uh breaking barriers bypassing Next Generation Um uh TFA and MFA implementations uh as the host said my name is Shamir rair and I am going to be talking to you about this particular uh uh session today and uh hopefully not not disappoint you with it so uh I hope that it is visible to all of you let me just full screen yeah

okay uh yes here's a little bit introduction about myself uh I am sh ahir and I have uh been you know recognized as the third best Bug boundy Hunter globally I have been in this field for the past lots of lot lots of years actually and uh I have been doing BG bounty hunting for the past seven years right now I am basically leading my own consultany

company and uh doing you know multiple startups at the same time okay so today agenda for today is uh um you know we are going to talk about TFA how it evolved over the years we're going to talk about implementation of TFA and MFA we are going to bypass tofa and web and mobile applications we're going to bypass MFA using logical flaws and then you know we

we're going to just see if we have time left to do all of the other things okay so let's talk about a uh TFA two Factor authentication is basically an identity uh and access management security method basically someone uh thought of TFA I don't know who it was but they thought of tofa uh as a security measure to implement you know uh to solve the problems when

it came to passwords because passwords are non rotatable they are they're they they are tied to user accounts and we needed to have a system in place that could be that could replace passwords so that's why PFA was created uh and then you know someone else thought about the idea okay these tokens can be tied to hardware and user Biometrics because at the end of the day

it's the token itself right so then they created MFA but TFA and MFA are similar in a way that they that behind every authentication mechanism there is a token and that token is is what drives forward the working architecture of TFA is in four processes or four steps we have the application authentication we have the login we have the OTP generation we have the OTP delivery basically

all kinds of TFA mechanisms can be you know devised into these aspects actually uh and uh you know going down the line we have so all of the TFA and MFA implementations that you see online all of them basically can be uh summarized into the following methods that you see on screen all of them can be um you know compressed into the following methods we have SMS

we have the user Biometrics we have uh the time based thingy the push notifications the challenge the email the pho UTF every TFA and MFA implementation can be summarized into this and every bypass of TFA and M TFA in web and apps can be collectively summarized into these 10 methods T will be either boot Force there will be a session flaw it'll be compromised using csrf there

will be a code reusability function the request method problem the Response Code manipulation the input parameter manipulation C code will be leaked there will be a bypasses um and or either there will be forced browser so let's look at the first one Brute Force Brute Force we know what it is right it is basically a common type of attack that uh relies on the guessing game like

we have to guess the p we have to guess the right code Tok C methods that are not time based or victims to attacks before we move forward let me just tell you how we are going to go about with this I'm going to explain an attack and then I'm going to explain the relevant examples or the relevant case studies that were uh present with that attack

so for for example we are going to uh we explain what root forces maybe we already know then I'm going to show you an example and this example is of grab uh we know what grab is right we we we know what it is we we have seen grab uh before we have used grab before we know what it you know basically is it is a company

that is a ride hailing app that was basically that works basically in Malaysia and uh what you see on your screen right now is uh what what happened in grab basically their TFA code was you know being believed uh sorry the profile the tofa code was being brute force and we had to check uh the content length of the responses uh to differentiate which was right or

which was wrong the parameter was called uh sorry the parameter was called um uh profile activ ation code and uh you know if we Brute Force the grab uh uh you know this particular parameter the wrong tries would result 617 response and the correct one resulted in a 2250 and that is how we basically came to know that grab had this particular you know problem uh now

uh moving forward um slack was also um you know a victim of this kind of attack um we had a similar problem in slack once and the issue was that slack had uh it was a password reset token and the user requested a password reset token they visited the password reset page and then they would get redirected to the endpoint but the problem was that there was

no rate limitation on the TFA endpoint after the password you know reset uh token and this was very ironic by the way dash lane it's ironic because dash lane is a password Walt and U password Walts are usually supposed to keep our password safe right but it was very ironic because dash lane was vulnerable to a Brute Force bypass in there to a fake Cod uh so

this was by the use of headers actually and U what happened was that X forwarded for or X forwarded host headers are basically used to um do a couple of things uh you know including but lot limited to uh specify the origin of a particular request and this is what happened in this particular case as well um when we were brute forcing the TFA it was uh

you know the the origin of the request was not stated and because the origin of the request was not stated um there was a problem and uh the server thought that the request is basically coming from itself and it not it did not you know stop it and uh another very very uh interesting case study that we identified this was in Microsoft and uh you know this

is very interesting this was not tofa this was not only related to tofa but it resulted in a complete takeover this is a gist of it but Microsoft uses tofa for loging purposes for payments you know almost everything and uh what Microsoft did was there were two problems in this particular case Microsoft was not verifying the reality of the IP address and verifying the the number of

concurrent uh requests at a particular time so what we had to do was we had to very simply and fairly come up with a scenario where we generate concurrent request for the same account at the same time from all those IP addresses so what happened was that we had the the the tofa code consisted of 11 million possibilities so we generated a list of 11 million fake

dummy IP addresses we we created a script that would you know spoof the origin IP and send 11 million such requests at the time and uh combining both of these vulnerabilities it worked we were able successfully um you know hack into a Microsoft account using this particular uh vulnerability or FLW okay next broken session management um this is basically a typical non-typical different scenario um broken session

management or authentication is a flaw where uh the login sessions are not properly handled or the login session management is weak and the first um scenario that we listed this in identified this and was in Facebook Facebook was basically passing the user ID and the nons cookie ID in in the URL parameter itself and um and this was in the Donate option so if you would uh

if you would click that uh you know uh uh donate from any organization you you will redirected into the to an endpoint and if you copied that link and you you know used it from another device you would log into that particular account that clicked on the Donate link so this bypasses all authentication measures and tofa measures simultaneously so this was very next came in mapbox uh

mapbox is an online uh mapping API uh that is uh you know basically used and uh this was a problem in mapbox that you know mapbox basically redirected you to um mapbox basically um uh your uh internal session after the password uh was reset but uh uh if you had tof enabled um mapbox did not ask you for a tof code uh after the passport reset took

place so uh this was a very uh you know fine peculiar example that we identified in map box um moving forward uh this was very interesting and I I I think that these uh uh probably these videos are going to be available uh and you you will be able to see it because I think the streaming speed is perfect but uh in this particular case um we

bypassed Instagram's uh U iOS uh T and uh this was because of this particular problem I don't know if you can clearly see it or not but it was a problem in the secure here uh configuration system so I have a video of this and I'm going to show you to you it's in the slides it's probably visible to all of you uh um so so this

is between a victim and an attacker the Vic the attacker is requested an email change on behalf of the victim and the victim has basically uh declined that request and the attacker is going to get a notification uh regarding that and this particular uh system is basically abusing that particular um you know functionality so uh um I think that um this is a very interesting concept concept

and I think that this is a very uh um interesting uh we have to deal with so yeah I think we're going to move uh move forward with it just going to turn off my video so it is uh you get a better reception and you are shortly going to see that the victim account has been taken over successfully I hope uh you know this was an

interesting demo see anyway Let's uh move forward uh now we're going to talk about csrf csrf is basically uh a scenario where um you either disable the tofa of a particular account or you either uh you know um use a scenario where you are able to successfully uh uh change the users toofa phone number so uh and this was another very amazing great example that we had

in a website called M Ru and uh what happened was that M Ru basically had a um a problem in one of its partner websites called Pand out. Ru um which was uh that uh uh it was not having any any csrf token on its TFA so what potentially could happen was that uh an attacker would craft a page a specific uh page and uh that specific

page what it would do was that you know it would uh uh Force the user to disable their tet and this was what what was happening with Pand out. then we have something called code Reus ility now what code reusability does is in this particular case would be that it um allows an attacker to use a previously used TOA code this was a problem in WordPress um

and this particular problem was that wordpress.com was allowing old tofa code so uh if I have a tofa code that I acquired when I was activating tofa I can use that tofa code as many times as I as I want to and no other tofa code would be usable then there was a problem uh in the tofa then there's a scenario where the tofa codes are uh

actually uh being leaked and now this very interesting because this comes in one or two forms either the TFA code is being leaked in the request or the responses or it is being leaked in the application Source or somehow in the algorithm itself this was another very interesting case study or a very interesting scenario where uh the TFA code was being generated on the client side itself

so when you would request it to a fake code it would generate it on the client side store it on the server and then compare the generated code so essentially you were getting the code that you were own generating from your own side and uh yeah and then there is this uh this is also very very interesting and one of my favorite tofa bypasses by the way

you must have seen uh the uh you you the the QR code that basically you know comes in uh when you are basically requesting to activate your TR right that QR code is based on a secret key and that secret key is is basically the entire reason behind your TFA implementation and uh if somehow someone would get access to that secret key they could disable your tofa

or attach their own account to your tofa and you know you're you're basically a goner and we faced a similar uh similar issue so this was basically a team management app that we had and this app what it did was it uh uh what it did was it basically uh allowed the uh non-admin user to view secret keys of other uh uh other team member so uh

and we checked it out we basically um when we check the burp Suite request uh and and we sent it to the repeater the responses contain the tofa uh secret key values uh and what we could do was we could then take those secret Keys create a QR code out of them scan them with or Google Authenticator or whatever and then we would essentially attain access to

uh the entire session uh in that particular case and as you can see uh in front of your screen you have the particular disclosure uh of that secret key and we would we could very easily take over user accounts and you know cause all sorts of Mayhem then we have something called the input parameter poisoning now there are more than one ways to explain this but uh

this basically allows an attacker to create an HTTP request uh that they can uh um you know with their own specified or uh values of their of the parameters so something like this actually if and this was in glassor we all know what glassor is the biggest you know um HR classified internet in simple terms if you sent a blank code or if you sent a null

bite um you could essentially bypass glass doors Toof not in the original request but by intercepting that request and then you know removing uh the code itself you could very easily bypass glass doors to a f and uh same thing was in PayPal um and this was also a very very highly interesting scenario in PayPal that uh you know when you go to PayPal's login function and

you go to the alternative option which is the secret question and Al that sort of stuff and you you um you intercept the the the request of those answers and you remove the challenge and Fields uh the the backend application does not verify that and this allows you to take over potentially any user account on the internet this allows you to take over essentially all user accounts

um you know that PayPal has and this allows you to potentially cause uh you know this this was uh this was rewarded by PayPal and we uh you know when when we identified that PayPal actually took it very seriously and resolve this so this was this was a very big uh vulnerability okay this is also very interesting response manipulation we have request manipulation and then we have

response manipulation response manipulation is the the activity of changing the responses that you get from the server and forcing that response back to the server I have a very awesome example example for this uh that's that I'm going to show Down the Line This is the simplest version of it but um uh the awesome example is about basically an account with a tof a valid tof would

give would get you uh in in Json uh a true response and an invalid tofa would get would would basically get you uh a false response now in this particular case um you can change that response back to true and what you can do is you know after changing that response back to true you can force the server to accept that response and once the server accepts

the that response you can uh you know fairly easily um bypass the to a fade take it a bit further uh The Next Step would be to for the server to accept that particular respon response and um what what would you do you would then the server would ask you the cookie or the authorization Bearer and then you provide that and you can bypass that as well

with the responsible ination technique this is another um very amazing and awesome example uh you enter the victim's ID and password and you intercept the request copy the MFA value and you again after the OTP you paste that uh you know NFA MFA value uh save from the response and by simultaneously changing the previous values with the stolen one uh you can bypass to a fa as

well okay one of my favorite examples of this entire session is this so this was a problem in one of the ewallets in uh finja actually that we had and that particular problem was that we were that uh fin was not basically responses so they had six different mechanisms and uh they were sending requests and responses the from the server encrypted like after even after SSL encryption

they were encrypting responses with a secret key within the app itself and uh so we had to identify First the decryption mechanism and then the correct uh response so what we did was we dug into the application and we found out the encryption key that was stored in the then we decrypted the responses that the the we decrypted all of the responses positive and uh we interchanged

the values for specific user accounts with those positive responses and you're going to see in the next video in which I'm going to probably keep quiet that how how it really happened but we bypassed four steps of authentication by chaining two vulnerabilities the disclosure of the key and second were the the response manipulation so we basically bypass tofa using two of these VN abilities so uh and

you know please enjoy this video that that you're going to see uh in the next slide it is a very amazing video and I have done my best to explain as much as I Soo of commentary guys um by now you must have known or identified you know all of the possible outcomes uh of the of of that particular case and of that particular scenario so as

you can see everything bypassed everything done and now the application is going to crash but we have all of the we have all of the required uh data we have taking over the user account and this way we were successfully able to take over all user accounts that word in I've have gotten a note that we have 10 minutes left very sad though uh I was hoping

we could have uh I could riffle through easily but this is another example guys uh that I wanted to that I wanted to show you uh I'm sorry about the sound this was something called shape shift now shape shift is a interesting application that allows you to convert cryptocurrency and we had their same response code manipulation in St uh you know um and we could essentially manipulate

their response codes and take over any user's account via tofa so this was a this was by one of my friends called Ian rord and we were uh it was uh his research originally and uh we combined it so uh moving forward we uh again the response codes were being manipulated and that's why we were successfully very successfully able to bypass tofa uh and I'm going to

riffle through uh quickly because I want to cover most of it then we have something called random backup codes now in our research we have identified that three out of 10 apps do not Implement client side checks when it comes to backup codes so you can essentially manipulate the request using input parameter manipulation remove all the backup code from that particular then forward that request and it

would get accepted three out of 10 apps do it and uh it is it works something like this this was another unknown site we able to say in a website we knock down the backup codes and uh after entering the email password we went to the recover option and use backup code option and we entered random backup codes or zeros and to our surprise that was accepted

and uh it was an eye openening fact that in our research three out of basically uh do it so yeah this is another very interesting scenario uh and I think this would be the last one that I would cover there are multiple request methods get head put post tax and delete in my research I identified that if you hit a tofa or MFA API and you use

the delete method the delete method disables TFA completely and uh that that happens a too and this is another very interesting method of bypassing tofa if you have social logins make sure you implement TFA on all of those social logins because uh hold this because this was uh this is called relay IQ it is now known as Salesforce IQ and uh uh what happened was that uh

the social logins did not have tofas uh in their uh in their mechanism authentication mechanism so if you clicked on any one of these links you would not be asked for uh a t uh code let's R through this skip this uh probably skip this interesting though let's talk about bypassing MFA uh and I'm going to give you a very brief uh walk through in this and

we can probably cover it all uh next time or an inperson talk when I come the Cyber wise con next year but this is also a very interesting thing MFA can essentially be bypassed using these seven methods uh and these seven methods are fishing kits Legacy protocols fatigue attacks voicemail Sim swapping MIT and wireless guest Network MFA is a broader thing it is used in uh it

is used in uh places where um in Enterprises in uh in multiple other uh you know um places where where there's a requirement of Hardware tokens or user Biometrics or stuff like that so MFA can essentially be bypassed using all of these scenario now quick walk through would be fishing kits are now using VNC protocols they're not using web browsers Legacy Protocols are IMAP and all of

that you know pop three and that stuff that do not have to affend their architecture so if you can force an Enterprise or an active directory to authenticate using uh Legacy protocols that is also a very uh you know awesome scenario fatigue attacks this was something that was uh done by that that Uber was compromised with that the attacker was basically sending in a lot of uh

to login requests and the victim just had to identify that then we have voicemail now if if the user is busy on a call the call is sent to voicemail and there are options where you can where you can request a c to a fake code using call and if somehow you can force that code to a voicemail and extract that information from that voicemail you would

essentially be able to buy by pass effect then we have something called Sim swapping uh which is a very in scenario in MFA Sim swapping basically refers to a scenario where you are able to clone the users uh you know Sim onto your own system then we have mitm based fishing uh and wireless guest Network so uh I think we are just about done with time so

I'm just going to show you what was left and uh riffle through the end of the stuff what we have done is we've we have sort of my research is based on TFA and MFA for a lot of years now and we' have culminated that into a single solution uh but uh at the same time I would uh you know just like to tell you all that

if you have any further questions about the presentation you can reach out to me over LinkedIn or my name is sham you can search me there or you can email me and I would be more than happy to answer them but yeah we are uh just about done with time and uh I think that uh if uh we have any questions from the audience I would be

more than happy to uh you know take them but uh I hope that that was interesting and I hope that uh this presentation was an eye opener for you not to rely on passwords or t to do your own research whether you are doing bu bounty hunting or whether you are doing you know your personal research you should have uh you should have your own perspective on

it and hopefully next year I would be able to give a very broader and in depth talk about this uh going forward but yeah that's uh that's about it for me yeah that's that's that's it thanks a lot uh Shakir um super interesting uh looks like we cannot trust tofa anymore but uh I'm checking if there's any questions at the moment we are running completely out of

time actually we have according to this yeah we are running out of time uh thanks again for participating I hope to see you in further editions of devops pro and for the people that are still watching we are going to be back in five minutes for the next session so stay tuned and see you in a couple of minutes thanks byebye bye guys take care see you

all next year