How “Forgot Password” can cost you your account

Thexssrat
5 min readMay 21, 2022

Password reset link not expiring

After a user has used a password reset token, that token should be burned and should not be used for that account again. The problem is that sometimes developers forget to invalidate these tokens. This would allow several attack avenues such as the attacked being able to generate an infinite amount of tokens because the…

--

--

Thexssrat

No b*llshit Hacking tutorials with extreme value in short bursts