PornHub: Email Confirmation Bypass
Reporter : Vaxo Dai (@___0x00)
After signing up client needs to verify his email address to further use but the confirmation can be bypassed and can put any email address to confirm the user account
http://www.pornhub.com//user/confirm?id=[idname]&code=[code]
Here, user can get this id name using
pornhub.com/users/[username] and viewing the source.
For longer description and POC :
https://youtu.be/XFGjcfwXoqM (Beware, you might get boner xD )
Thanks,
This is the case of brute forcing, there is no such limit attempts, unlimited attempts can be done, to get correct confirmation code
PornHub Reply To Report :
So from what you describe, it’s possible to retrieve the ID from the page source and the confirmation code would be brute forced. This is possible but unlikely given that an attacker doesn’t gain much from going through the effort. I’m having trouble seeing the security implications. Closing as informative.
