Web Security

Two Captcha Bypasses — IDOR and Token Reuse
Two Captcha Bypasses — …

This is my first write-up here. I will talk about how I bypassed captcha on two companies.

First One (Captcha Token Reuse)

While testing a site.example.com, I found that signing up on their site had a captcha. I solved the captcha challenge and captured the request with credentials, and I saw the …