How I Bypassed OTP Rate Limits and Earned $303 in a Bug Bounty Hunt
hello gyussssss
How I Bypassed OTP Rate Limits and Earned $303 in a Bug Bounty Hunt
hello gyussssss
i am loke here with a new bounty tail that i recently rewarded for 2fa bypass . i just love 2fa issues
lets start :
that was a normal day i was hunting for high level issues . i was doing recon to get another bug . on a public program . but no luck i don’t get any issue that i can exploit and get bounty .
suddenly i say a login panel where a user can login to there account and after that i saw a ip-code-confirm from where a user need to confirm there otp using there email .
i was surpriced when i say that the code only use 4 digit otp . i was like what the hack , still using 4 digit code to configure the otp .
i start testing manully to that then i found that ther is no rate limit form on this verifaction page .
the page was like ‘https://auth.target.com/user/login/ip-confirm-code'
then i start brute forcing the otp to get login to user account . i saw there is no validation on attempts for verification the otp . after successfully login to users account . confirmed that this is an issue but its p4 .because its just a rate limit bypass . i need to create more impact .
so i think , how to incress impact . i was reading article on medium i say a article where the rate limit bypass is accepted as 2fa bypass p3 .
quickly i create report and submit it to bugcrowd .
guess what i get from bugcrowd :
- teapot_bugcrowd changed the state to Not applicable

- teapot_bugcrowd sent a message
- Hello,
- After reviewing your report, we were unable to identify any security impact. As such, this has been marked as Not Applicable.
- In order to be a triaged issue, a submission must demonstrate an impact that can have an effect on the customer, the application/website, or its users. Submissions should always answer the question, “as an attacker I could”, with a suitable demonstration of such. Findings that reveal points of information or security best practices without an impact are not eligible for a reward and should be explored further in order to demonstrate risk. When you are able to demonstrate this, please do so in a new submission. We look forward to your future submissions.
- If you believe this has been closed in error, please raise a
Request for Responseto re-evaluate. - Best regards, teapot_bugcrowd
i was stunned and shocked . so i quickly create a response request and wait for the response . after 3 month i get the response and
when i get response . i was very happy .
Mogl1s sent a message
Hello LokeshSoni,
Thank you for your initial report, I have validated your finding and you should receive a bounty soon.
Kindest Regards and Happy Hacking
not for the bounty but for the ‘Kindest Regards and Happy Hacking’
HotChocoMama rewarded LokeshSoni $303.45
i was very happy to get this bounty . and ready to find another issue .
thank you hope you like this article .
메타데이터
- post_id
- 9e686274e5f4
- slug
- how-i-bypassed-otp-rate-limits-and-earned-303-in-a-bug-bounty-hunt-9e686274e5f4
- url
- https://medium.com/@lokshsony/how-i-bypassed-otp-rate-limits-and-earned-303-in-a-bug-bounty-hunt-9e686274e5f4
- canonical_url
- https://medium.com/@lokshsony/how-i-bypassed-otp-rate-limits-and-earned-303-in-a-bug-bounty-hunt-9e686274e5f4
- author_url
- https://medium.com/@lokshsony
- status
- ok
- fetched_at
- 2026-06-09 18:04:40