0-Click Account Takeover via Insecure Password Reset Feature
If you enjoy what I do, please support me Buy Me Ko-fi! https://ko-fi.com/h0tak88r
subfalcon -l domains.txt -w "YOUR_DISCORD_WEBHOOK_URL" -m
javascript:(function(){var scripts=document.getElementsByTagName("script"),regex=/(?<=(\"|\%27|\`))\/[a-zA-Z0-9_?&=\/\-\#\.]*(?=(\"|\'|\%60))/g;const results=new Set;for(var i=0;i<scripts.length;i++){var t=scripts[i].src;""!=t&&fetch(t).then(function(t){return t.text()}).then(function(t){var e=t.matchAll(regex);for(let r of e)results.add(r[0])}).catch(function(t){console.log("An error occurred: ",t)})}var pageContent=document.documentElement.outerHTML,matches=pageContent.matchAll(regex);for(const match of matches)results.add(match[0]);function writeResults(){results.forEach(function(t){document.write(t+"<br>")})}setTimeout(writeResults,3e3);})();


https://brandcentral.target.com/mars/reset.hash_reset?p_hash=B367AD4F&p_sign=4ixUHUGmhW6YZ6VyKCdzxoqAaaU%3Dhttps://brandcentral.target.com/mars/reset.hash_reset?p_hash={FUZZ}&p_sign=
PreviousExploring Subdomains: From Enumeration to Takeover VictoryNextHow a Simple Click Can Lead to Account Takeover: An OAuth Insecure Implementation Vulnerability
Last updated





