Host Header Poison lead to account takeover

8 months ago 35
BOOK THIS SPACE FOR AD
ARTICLE AD

While iam testing private program at hackerone i told to myself to start with host header poison in reset password (my lovely bug)

I have a list of ways that i do at any bounty program in host header to bypass host validations.

ways:

1- Host: attacker.com/target.com

2-attacker.com/.target.com

3-target.com.net or target.cc or attacker.target.com

and another ways that i use

In our private program i bypass host validation with target.io.burpcollabrator.oastify.com

and as expected i got host header poison at reset password that leads to account takeover

Read Entire Article