Account Takeover
Chain weaknesses in auth, reset, and session flows to seize another user's account.
Tags: ato, auth, logic
Level: advanced
Method
Map every auth surface
Login, register, password reset, email/phone change, OAuth, MFA, and 'remember me'. Each is a candidate.
Tools: Burp Suite, Caido
Attack password reset
Test host-header poisoning of reset links, token predictability/reuse, and reset-token leakage in responses.
Abuse response manipulation / OAuth
Look for client-side auth decisions, OAuth redirect_uri flaws, and pre-account-takeover via unverified email.
Bypass MFA
Check for OTP brute-force (no rate limit), response tampering, and backup-code enumeration.
Field notes
- Host-header poisoning on reset emails is still shockingly common.
- Race conditions in reset/verify flows can bypass single-use tokens.