Web Account Takeover

Systematic account-takeover hunting — password reset, email change, session, and linking flaws that seize another user's account. Load on "ATO", password-reset/forgot flows, email-change, OTP/2FA, "login as", session handling. Signals: reset tokens, email-change without re-auth, OTP, magic links.

NoorQureshi Updated

File contents

NoorQureshi/SploitAgent/tree/main/skills/web/web-account-takeover commit a811793c1c

Frequently asked questions

npx skillmds@latest add noorqureshi/web-account-takeover