Otp Bruteforce Testing

Detect, validate, and exploit OTP (one-time password) brute-force vulnerabilities in phone/email verification, MFA, password-reset, and transaction-confirmation flows. Use when a target issues numeric one-time codes (4-8 digits via SMS/email), when OTP verification endpoints appear unthrottled, when reviewing authentication or account-recovery code, or when assessing rate limiting on verification APIs. Produces PoC scripts, response-oracle analysis, CVSS scoring, and remediation guidance.

SecurityTalent Updated

File contents

SecurityTalent/bugskill-ai/tree/main/Personal-Claude-Code-Agent-Skills/otp-bruteforce-testing commit 4c20960961

Frequently asked questions

npx skillmds@latest add securitytalent/otp-bruteforce-testing