Posts

Showing posts with the label hacking

The Curious Case of Hidden Phone Number Change & POST-to-GET CSRF — A Hacker’s Tale

Introduction Sometimes, the most interesting vulnerabilities aren’t the flashy ones — they’re the sneaky, almost accidental bugs that show just how broken the logic behind a system can be. This is one such story where a "simple" password change page led me down a rabbit hole, exposing insecure phone number updates, exposed JS files, and a site-wide CSRF risk. The Setup: A Weird Account Settings Page I was casually poking around a web application’s user settings section when something immediately stood out: There was only an option to change the password — no UI to update email , name , or even the phone number . This felt odd for a platform that relied heavily on phone-based verification. The Discovery: A Phone Number Change Endpoint Hidden in Plain Sight I decided to do some digging, and sure enough, a JavaScript file revealed an unused (and undocumented) phone number change endpoint . However, the parameters required were unclear. I had no documentation, and the request w...

The Reset Password Attack Vector

  Hey Guys, Recently I have seen this attack vector mostly. While resetting the password check for any redirect,callback,returnurl paramters in the post body. Or try to param bruteforce it using any tool like param miner. and try to change it to a custom bind payload. { "email" : "victim@mail.com" , "Fuzz" : "burpcollabarator/customclient" } and try that you getting the payload link in the email.