Security question bypass
While trying to log in into my account on https://account.mojang.com i could just remember one of the three security questions answeres that I was sure of. (Set them 6 years ago
)
In browser developer mode I found hidden input fields along with the answer text fields containing a question ID. (See attachment)
By changing the second and third questionId field's values to the value of the first questionId field and supplying the correct answer of question one to questions two and three I was able to get into my account *without * knowing the correct answers for all three questions!
FYI I discovered this purely by accident without malicious intentions! The account used for this is mine, no other accounts were compromised!
If reported incorrectly please forward this report!
Thanks for your time, best regards ![]()
Maximilian Radoy
Edit: Should be checked whether you could use questionIds from another account (eg the hackers account to get into another account)
2017-05-24, 12:03 PM
2019-04-13, 05:32 AM
2018-11-07, 07:06 AM
4
3