SECURITY
search
Ctrlk
  • Enumerationchevron-right
  • Content Discovery
  • API hacking
  • CORS Misconfiguration
  • XSS
  • SSRF
  • Account take over
  • IDOR
  • Access control vulnerabilities and privilege escalation
  • HTTP Request Smuggling / HTTP Desync Attack
  • Subdomain Takeovers
  • Resources
  • 403 Bypass
  • Log4J
  • Bypassing Client-Side Controls
  • BACKUP FILES /Backup Archives:
  • Attacking Authentication
  • DNS enumeration/DNS recon-reading
  • Subdomain Enumeration-reading
  • Subdomain Takeover
  • File upload vulnerabilitieschevron-right
  • CRLF
gitbookPowered by GitBook
block-quoteOn this pagechevron-down

Account take over

Youssef Sammouda (sam0) personal blogYoussef Sammouda (sam0) personal blogchevron-right
https://medium.com/r?url=https%3A%2F%2Fnotifybugme.medium.com%2Fchaining-cors-by-reflected-xss-to-account-takeover-my-first-blog-5b4f12b43c70medium.comchevron-right
PreviousSSRFchevron-leftNextIDORchevron-right

Last updated 1 year ago