Signing in as an administrator without a password

This host is the attacker in a report filed against @auth0/nextjs-auth0. Everything below runs in your own browser against a demo application. No account needed.

1 Sign in to the target the normal way

Open f11-app.huntland.abiusx.com and press Sign in. Use the demo account:

alice@corp.example
Sunflower-Ladder-91

You land on the portal as Alice Weber, role user. Open the Admin console and the application answers 403, because Alice is not an administrator. Press Log out before continuing.

2 Confirm you cannot reach the administrator account

Press Sign in again and try admin@corp.example with any password you like. The login server rejects it. The administrator password exists only inside that server and is never handed out.

3 Now take the administrator account

On the target's tab, open DevTools, then the Console, and paste this one line:

Press Sign in. No password is asked for. You arrive as Priya Raman, role admin, and the Admin console opens.

4 Read what the target sent me

The sign-in above routed the target's login through this server. Open /captured to see the target's OAuth client_secret arriving here. That credential is shared by every user of the application.

The cookie value is what does the work. The target reads it into a fixed template of the form auth.<brand>.huntland.abiusx.com, so the value should never be able to leave that suffix. The @ moves the hostname to a domain I own.