
Able to Takeover Merchants Accounts Even They Have Already Setup SSO, After Bypassing the Email Confirmation Summary This report is based on the scenario that email confirmation has been bypassed already, like shown in #791775. What happened in #791775 was, I was too excited and didn't take a step further to try to takeover merchant's account even they have SSO setup, and after reading the comment An important mitigating factor was that this bug only affected user accounts which had not yet adopted our single login system., I know I have to find a way to bypass that to prove my point. Description For merchant that have accounts already setup SSO, even attacker has bypassed the email confirmation, they would have no ways to takeover the rest of the accounts of the merchant, because they will need to enter the master password of the merchant in the process of merging accounts. Let me illustrate this in graphs, in this example, the merchant that has SSO already setup is [email protected], the attacker sign-up a store h48ngalog.myshopify.com, with email [email protected] Stage 1. First, for whatever reason, maybe a new feature appeared that allows attacker to bypass email confirmation again or an old bug bypass, that as an attacker with [email protected] confirmed, he should see this in the shop {F716958} Stage 2. Then, when attacker clicks Review accounts, attacker needs to put in the store password first, which is fine cause attacker signup this...
SOCIAL SHARE CARD GENERATOR