Loading HuntDB...

SMS URL verification link does not expire on phone number change and lacks rate limiting

Low
U
Uber
Submitted None

Team Summary

Official summary from Uber

When verifying your phone number attached to your Uber account, it was possible to re-use an old verification URL to validate a new cell phone number. In addition to this, there was no rate limiting on the SMS verification which allowed for it to be easily brute-forced. The internal team resolved this by removing the ability to perform SMS URL verification in favor of a standard 4-digit verification. Thanks, @hanuman1!

Reported by hanuman1

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Authentication - Generic