1 Web App Hacking Password Reset Functionality m1 Slides
1 Web App Hacking Password Reset Functionality m1 Slides
1 Web App Hacking Password Reset Functionality m1 Slides
Dawid Czagan
SECURITY INSTRUCTOR
@dawidczagan
Overview
Password reset functionality
Implementations
Attacks
Very sensitive
operation
Account takeover
Implementations
https://example.com/reset.php?token=38d527c93b748a2
https://example.com/reset.php?userID=3451&token=38d527c93b748a2
Generating New
Password
Secret Question
and Answer
Attacks