vulns.co
/
GKData.io MCP

Reset and magic links

A reset or magic link is a bearer token in mail. Record who receives it, whether a second browser can use it, and whether it still works after the first use. Use a mailbox you own.

Skill: Session, cookies, and passkeys

Ask: Which cookie or token does the server trust, and can recovery issue a session the primary login would not?

Stop: You can name the cookie or token, the recovery path, and whether a second browser still holds a session after logout.

Open the skill

Practice the class in the browser: PortSwigger Web Security Academy. The lab is theirs. This page is the stop condition and the disclosures.

Checklists

None linked for this class yet.

Disclosures

No public card yet.

Playbooks

  • Reset and magic-link binding - A reset or magic link is a bearer token delivered through mail. The questions are who receives it, whether it is bound to a browser or session, and whether it can be used twice.

Tools

  • Burp Suite - The industry-standard intercepting proxy for manual web testing. Community edition is free; Pro adds the active scanner and automation.

Questions

The link works in a second browser. Is that account takeover?

Not by itself. Many products intend the link to be a bearer token. It becomes a finding when the product claims the link is bound, or when it stays valid after use, or when it is delivered to a mailbox the account should not have.

Where does the host-header bug go?

On the host-header notes inside the reset playbook, then the session hunt if the cookie is the impact. Do not file one poisoned host as three reports.

This page is the linked pack hunt_brief("reset") returns on the MCP connector. Authorized testing only.