The Reset Password Attack Vector

 

Hey Guys,

Recently I have seen this attack vector mostly.
While resetting the password check for any redirect,callback,returnurl paramters in the post body.

Or try to param bruteforce it using any tool like param miner.
and try to change it to a custom bind payload.


and try that you getting the payload link in the email.

Comments

Popular posts from this blog

The Curious Case of Hidden Phone Number Change & POST-to-GET CSRF — A Hacker’s Tale

Android pin bypass with rate limiting

💸 "65 Euros for an Account Deletion Fail — When Deleted Doesn’t Mean Deleted"