Hunt Ato

"Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains. Paths: (1) password reset flaws (host-header injection redirects token, predictable/numeric token, Referer leak, no-expiry/reuse), (2) email change without re-auth, (3) OAuth account-link CSRF, (4) MFA bypass (per hunt-mfa-bypass), (5) session fixation, (6) JWT manipulation (forge token to another identity; crypto details → hu

wufufu770 Updated

File contents

wufufu770/skills/tree/main/ext/2-web-vulns/030-hunt-ato commit 4f74ecdd00

Frequently asked questions

npx skillmds@latest add wufufu770/hunt-ato