BOOK THIS SPACE FOR AD
ARTICLE ADJust now
--
While iam testing private program at hackerone i told to myself to start with host header poison in reset password (my lovely bug)
I have a list of ways that i do at any bounty program in host header to bypass host validations.
ways:
1- Host: attacker.com/target.com
2-attacker.com/.target.com
3-target.com.net or target.cc or attacker.target.com
and another ways that i use
In our private program i bypass host validation with target.io.burpcollabrator.oastify.com
and as expected i got host header poison at reset password that leads to account takeover