way to bypass Paypal's two-factor authentication (2FA), the vulnerability lies primarily in the authentication flow for the PayPal API web service (api.paypal.com). And now once again a teen white hat hacker claim to found a way to bypass the Two-Factor Authentication of the Paypal system.
A young teen Joshua Rogers from Melbourne, Australia, have claims to bypass the Two-Factor Authentication (2FA) system PayPal uses to protect user accounts. Rogers explains that the bypass process requires little more than spoofing a browser cookie set when users link their eBay and PayPal accounts.
He further explained that once the cookie—which is tied to a function, which PayPal identifies as "=_integrated-registration" is active in a user's browsing session, then the two-factor authentication of Paypal is bypassed. In simple words, it means that Paypal didn't check for the 2FA code while logging in.
This means if the attacker somehow gained some of the login credentials then the attacker can also access the Paypal account of the victim without entering the one-time passcode sent to the account holder's mobile phone. [Note- Both eBay's and Paypal accounts should be linked for this process]
In an ethical way, Rogers reported the issue to the Paypal security team on 5th June. But after two months with no response from the Paypal team, he makes it public.
Once you're actually logged in, a cookie is set with your details, and you're redirected to a page to confirm the details of the process. And this is where the exploit lays. Now just load http://www.paypal.com/ and you are logged in and don't need to re-enter your login.As the technique does require a victim password, but the scene shows the flaw in the 2FA system of Paypal, which didn't ask for one-time passcode (OTP) while logging into a Paypal account.
So, the actual bug itself is that the "=_integrated-registration" function does not check for a 2FA code, despite logging you into PayPal.
You could repeat the process using the same "=_integrated-registration" page unlimited times. - he wrote
Here is the POC video from Duo Security demonstrating their finding-