Password reset poisoning via middleware
Lab Description

Walkthrough
Step 1: Investigate the Password Reset Functionality

Step 2: Inspecting the Reset Link

Step 3: Testing with X-Forwarded-Host Header


Step 4: Observing the Manipulated Link

Step 5: Verifying the Exploit

Step 6: Requesting a Token for Carlos

Step 7: Resetting Carlos's Password


Step 8: Logging into Carlos's Account

Last updated