Breaking the Chain: Exploiting OAuth and “forgot password” for account takeover
bugcrowd.com | blog | #bug-bounty | #burp-suite | #account-takeover | #oauth | #forgot-password | #writeup
Summary
A write-up of two account takeovers shown at Ekoparty 2024: manipulating loginType and oauthId in an OAuth login flow, and abusing a 16-digit code in forgot-password, step by step with Burp Suite.
- Published
- Collected
Skip to content