2FA simple bypass | Apprentice
This excerpt from PortSwigger sums this up pretty nicely:
“At times, the implementation of two-factor authentication is flawed to the point where it can be bypassed entirely.
If the user is first prompted to enter a password, and then prompted to enter a verification code on a separate page, the user is effectively in a “logged in” state before they have entered the verification code. In this case, it is worth testing to see if you can directly skip to “logged-in only” pages after completing the first authentication step. Occasionally, you will find that a website doesn’t actually check whether or not you completed the second step before loading the page.”
So after we log in using carlos credentials, we can just skip straight to the main page while still logged in. The server does not bother to check whether we’ve passed 2FA or not. Very informative.