Password reset vulnerability on a website!

preview_player
Показать описание

Рекомендации по теме
Комментарии
Автор

I wish it worked like this 😭😭😭 they're not gonna get the email with your website

fgf
Автор

Who the hell generates the reset token on the frontend?

shriram
Автор

only downside is that most reset emails say to ignore it if you did not trigger it.

hyperkiko
Автор

If the host is changed to attcker ip then how the request went to the server? And not the attackers

codermomo
Автор

That is stupid! He's saying utter shite

fallegapyro
Автор

Funny 😂 if you change the host url to the attacker url, it will be making a request to attacker server and not the actual website server. So this video is junk bro 😂 and doesn't make any sense

adekojoadeyemi