vulns.co
/
GKData.io MCP

Back to Playbooks

Account Takeover

Chain weaknesses in auth, reset, and session flows to seize another user's account.

Tags: ato, auth, logic

Level: advanced

Method

  1. Map every auth surface

    Login, register, password reset, email/phone change, OAuth, MFA, and 'remember me'. Each is a candidate.

    Tools: Burp Suite, Caido

  2. Attack password reset

    Test host-header poisoning of reset links, token predictability/reuse, and reset-token leakage in responses.

  3. Abuse response manipulation / OAuth

    Look for client-side auth decisions, OAuth redirect_uri flaws, and pre-account-takeover via unverified email.

  4. Bypass MFA

    Check for OTP brute-force (no rate limit), response tampering, and backup-code enumeration.

Field notes

  • Host-header poisoning on reset emails is still shockingly common.
  • Race conditions in reset/verify flows can bypass single-use tokens.

References