The Reset Password Attack Vector

 

Hey Guys,

Recently I have seen this attack vector mostly.
While resetting the password check for any redirect,callback,returnurl paramters in the post body.

Or try to param bruteforce it using any tool like param miner.
and try to change it to a custom bind payload.


and try that you getting the payload link in the email.

Comments

Popular posts from this blog

Idor in google product

Creative Android pin bypass with Race conditon

The Curious Case of Hidden Phone Number Change & POST-to-GET CSRF — A Hacker’s Tale