April 18, 2023, 3:36 p.m. | Pawan Chhabria

InfoSec Write-ups - Medium infosecwriteups.com

Hello All, this is my first account takeover writeup and I hope it helps everyone. Taking over another user’s account is something that amazes everyone. There are several ways in which we can perform “Account Takeover”, but the one which I got is a bit interesting!!!

Account Takeover

Note: The domain and other details have been masked to maintain Confidentiality.

Forgot Password is the best possible feature where most of the “Pre-Auth” account takeovers happen, so I started playing around …

account account takeover auth business-logic confidentiality domain email hacking hello hope password request security takeover takeovers victim web app security writeup

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Senior Security Researcher, SIEM

@ Huntress | Remote Canada

Senior Application Security Engineer

@ Revinate | San Francisco Bay Area

Cyber Security Manager

@ American Express Global Business Travel | United States - New York - Virtual Location

Incident Responder Intern

@ Bentley Systems | Remote, PA, US

SC2024-003533 Senior Online Vulnerability Assessment Analyst (CTS) - THU 9 May

@ EMW, Inc. | Mons, Wallonia, Belgium