Session Based Bugs
Old Session Does Not Expire After Password Change:
1.create An account On Your Target Site
2.Login Into Two Browser With Same Account(Chrome, FireFox.You Can Use Incognito Mode As well)
3.Change You Password In Chrome, On Seccessfull Password Change Referesh Your Logged in Account In FireFox/Incognito Mode.
4.If you'r still logged in Then This Is a BugSession Hijacking (Intended Behavior)
1.Create your account
2.Login your account
3.Use cookie editor extension in browser
4.Copy all the target cookies
5.Logout your account
6.Paste that cookies in cookie editor extension
7.Refresh page if you are logged in than this is a session hijackingPassword reset token does not expire (Insecure Configurability)
Server security misconfiguration -> Lack of security headers -> Cache control for a security page
Broken Authentication To Email Verification Bypass (P4) :
Email Verification Bypass (P3/P4)
Old Password Reset Token Not Expiring Upon Requesting New One (Sometimes P4) :
Password Reset Token Not Expiring After Password Change (P4):
Insufficient account process validation leads to account takeover (P3/P4):
Authors
Last updated
Was this helpful?