Mojira Archive
WEB-2106

Mojang AUTHENTICITY EXPLOIT

Hi,i would like to present you authentication exploit that relies on authenticityToken.

So basically authenticityToken is the same in both windows and with reflex,or programatically sent request you can force to authenticate AuthenticityToken on account you should get Security Questions.

You need two accounts:

-One with Security Questions not sent

-One with done Security Questions

And a mouse MACRO to click LOGIN on both windows.

Here is a video example:

Fixed

David Rosley

[Mojang] Web Team

2020-04-15, 01:43 PM

2020-05-06, 07:26 AM

2020-05-06, 07:26 AM

0

1