Bypass admin panel access
Jitu Mani Das (CISM CISSP)
Cyber Security Expert (IT and OT/ICS) | Cloud Solution Architect | Security Operations | Enterprise & Critical Infrastructure Security Architecture & Design | IT and OT SOC Design & Built | FORENSICS
There are two approaches:
1. Technologies enumeration and then bypass accordingly.
2. Getting credentials from Leaked dbs
Technology related bypasses:
??NoSql/SQL injection.
??Force browsing.
??Response tampering.
??Exploiting mass assignment while registering for account/updating account.
Leaked Credentials:
??Getting credentials from Leaked dB's(osintleak.com ) a perfect platform for leaked creds.