Password reset floodcheck bypass

I just got another one 0 minutes ago :frowning:

This attack was different than yesterday’s attack. We have shut down this endpoint for now.

7 Likes

Hopefully you guys will find out who is behind this and take appropriate action. :slight_smile:

Could be a delayed email or an unrelated attempt by someone.

1 Like

I got hit with like 10 of these earlier.

I wonder whose behind this.

The attack method was different? So someone is actively looking for ways to spam emails to us? Nice.

Just received these emails, 5+ emails since last hour ago, hopefully this is fixed soon.

I got 5 emails, hopefully this is finally resolved

I’m still getting emails, they’re gradually decreasing the interval at which they’re sent.

Is this an after effect, or is there a different endpoint being abused now?

3 Likes

(referring to second bout of username based emails)

I’m pretty sure the person was using a legacy password reset endpoint under api.roblox.com, which accepted a username. It was actually listed under the /docs page until a few months ago.

I previously made someone aware of the legacy endpoint, however it was never removed. There’s no impact besides a slight annoyance, the endpoint was rate limited as far as I had tested it.

The first attack also had a relatively low impact on end users besides the sheer amount of spam, however could have been used to smuggle phishing emails in between the legitimate reset emails since the user had the targets email address. This isn’t possible in the method I mentioned in this reply, because the user does not have access to the targets email.

2 Likes

I am still receiving these but at the moment it’s at 4 and the latest was about 2 hours ago.

Just received another a second after this post.

I’ve received six of these over the past three hours. I received the last one 55 minutes ago.

1 Like

Received 4 emails between 05:30 and 07:45, and received my fifth a few minutes ago at 09:26. Whoever’s doing it, they’re an equal opportunist.

Just pointing out that these emails are most likely from a backlog and are only coming through now. If you visit the link, you’ll see they’ve already expired.

img1

2 Likes

Just changed my email… not sure if that was necessary.

It wasn’t. Someone was abusing the old API that required one’s username to prompt the password reset process. Nothing was leaked with it so rest assured.

Is there going to be an official statement on this? Seen quite a lot of people spreading misinformation on this (like this post for example). Don’t think that people who don’t have access to this category should be kept in the dark.

2 Likes

I didn’t get anywhere near that amount (as of the time of this post) but I still was bombarded at about 6 a.m. CEST.
Not sure why it’s being done, or how, but it’s definitely worrying.

1 Like

Still very actively receiving them.
It might be worth investigating a potential security breach.

3 Likes