all InfoSec news
HackTheBox - Forgot
March 4, 2023, 3 p.m. | IppSec
IppSec www.youtube.com
01:03 - Start of nmap
02:00 - Talking about Varnish, then looking at the website
03:40 - Poking at the Forgot Password functionality and showing we can enumerate valid users
06:25 - Discovering a username in the HTML Source
07:10 - Start talking about Host Header Injection, showing the page will use the Host Header when building redirects
09:28 - Using host header injection in the password reset, in order to send the user a link that …
hackthebox header host html injection introduction nmap order password password reset redirects reset send start talking username valid website
More from www.youtube.com / IppSec
Jobs in InfoSec / Cybersecurity
SOC 2 Manager, Audit and Certification
@ Deloitte | US and CA Multiple Locations
Advisory Red Consultant
@ Security Risk Advisors | Philadelphia, Pennsylvania, United States
Cyber Business Transformation Change Analyst
@ National Grid | Warwick, GB, CV34 6DA
Cyber Security Analyst
@ Ford Motor Company | Mexico City, MEX, Mexico
Associate Administrator, Cyber Security Governance (Fort Myers)
@ Millennium Physician Group | Fort Myers, FL, United States
Embedded GSOC Lead Operator, Events
@ Sibylline Ltd | Seattle, WA, United States