Account Takeover

Advanced account takeover (ATO) testing methodology for bug bounty and application security work. Use when testing or reviewing login, password reset, email or phone change, OAuth/OIDC/SAML/social login, magic links, session cookies, JWTs, remember-me tokens, CSRF on identity-changing actions, linked accounts, SSO/SCIM provisioning, mobile deeplinks or intents, web cache issues, request smuggling chains, exposed admin/debug endpoints, and any workflow where a flaw may let one user obtain another user's session, reset credentials, bind an attacker-controlled identity, or assume account control.

yafet-dev Updated

File contents

yafet-dev/bugbounty-codex-skills/tree/main/bug-type-skills/account-takeover commit 47b87231a7

Frequently asked questions

npx skillmds@latest add yafet-dev/account-takeover