← Back to list

How I Bypassed OTP Rate Limits and Earned $303 in a Bug Bounty Hunt

hello gyussssss

Lokesh Soni · 2026-03-10 09:01 · 1 claps · 2.2 min read
#hacking #ethicle-hacking #web-security-testing #2fa #2fa-bypass
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

How I Bypassed OTP Rate Limits and Earned $303 in a Bug Bounty Hunt

hello gyussssss

i am loke here with a new bounty tail that i recently rewarded for 2fa bypass . i just love 2fa issues

lets start :

that was a normal day i was hunting for high level issues . i was doing recon to get another bug . on a public program . but no luck i don’t get any issue that i can exploit and get bounty .

suddenly i say a login panel where a user can login to there account and after that i saw a ip-code-confirm from where a user need to confirm there otp using there email .

i was surpriced when i say that the code only use 4 digit otp . i was like what the hack , still using 4 digit code to configure the otp .

i start testing manully to that then i found that ther is no rate limit form on this verifaction page .

the page was like ‘https://auth.target.com/user/login/ip-confirm-code'

then i start brute forcing the otp to get login to user account . i saw there is no validation on attempts for verification the otp . after successfully login to users account . confirmed that this is an issue but its p4 .because its just a rate limit bypass . i need to create more impact .

so i think , how to incress impact . i was reading article on medium i say a article where the rate limit bypass is accepted as 2fa bypass p3 .

quickly i create report and submit it to bugcrowd .

guess what i get from bugcrowd :

  • teapot_bugcrowd changed the state to Not applicable

  • teapot_bugcrowd sent a message
  • Hello,
  • After reviewing your report, we were unable to identify any security impact. As such, this has been marked as Not Applicable.
  • In order to be a triaged issue, a submission must demonstrate an impact that can have an effect on the customer, the application/website, or its users. Submissions should always answer the question, “as an attacker I could”, with a suitable demonstration of such. Findings that reveal points of information or security best practices without an impact are not eligible for a reward and should be explored further in order to demonstrate risk. When you are able to demonstrate this, please do so in a new submission. We look forward to your future submissions.
  • If you believe this has been closed in error, please raise a Request for Response to re-evaluate.
  • Best regards, teapot_bugcrowd

i was stunned and shocked . so i quickly create a response request and wait for the response . after 3 month i get the response and

when i get response . i was very happy .

Mogl1s sent a message

Hello LokeshSoni,

Thank you for your initial report, I have validated your finding and you should receive a bounty soon.

Kindest Regards and Happy Hacking

not for the bounty but for the ‘Kindest Regards and Happy Hacking’

HotChocoMama rewarded LokeshSoni $303.45

i was very happy to get this bounty . and ready to find another issue .

thank you hope you like this article .


메타데이터
post_id
9e686274e5f4
slug
how-i-bypassed-otp-rate-limits-and-earned-303-in-a-bug-bounty-hunt-9e686274e5f4
url
https://medium.com/@lokshsony/how-i-bypassed-otp-rate-limits-and-earned-303-in-a-bug-bounty-hunt-9e686274e5f4
canonical_url
https://medium.com/@lokshsony/how-i-bypassed-otp-rate-limits-and-earned-303-in-a-bug-bounty-hunt-9e686274e5f4
author_url
https://medium.com/@lokshsony
status
ok
fetched_at
2026-06-09 18:04:40