Finding Phone Number (OTP Bypass) bypass in Porsche

Hello Everyone, In this article I am going to explain you How I was able to bypass the Phone Number OTP, or OTP bypass in Porsche via Response Manipulation.

Here’s How I did it.

Register First. (Also the application doesn’t checks for real email or a temporary email which can lead to creation of fake accounts.)
Step 1: Go to my.porsche.com
Step 2: After logged in, Go to “Profile Settings”.
Step 3: Scroll to “Phone Number Sections.”
Step 4: Select your country code and add a number.
Step 5: Click on “Save”.
Step 6: By enabling intercepting mode, provide any random 5 digit code.
Step 7: While intercepting, check the repsonse.
Step 8: Change the Response code to 200 OK From 409 and forward the request.

Thanks For Reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

Achievements🏆

All the mentioned companies below, I have reported security vulnerabilities for which I have either received acknowledgement as Hall of Fame or received monetary reward as Bug Bounties. 

  • Telekom.
  • Sony.
  • Dell.
  • Adobe.
  • Frill.Co
  • Lenskart.
  • NCIIPC RVDP. (Goverment of India)
  • Magicpin.
  • Vercel.
  • YourDost.
  • Porche.
  • Channable.
  • OpenMoney.
  • Uizard.