In this lab we take a look at how a password reset link can be poisoned using the X-Forwarded-Host header and ultimately direct the victim to a completely separate domain as they try to reset their password. By tagging the password reset token on to the end of the GET request, we are able to steal the victim's password reset token from the attacker controlled domain.
We then use this password token to reset the password of the victim.
Support This Channel
======================
Please like and subscribe, it means a lot!
Please buy me a coffee so I can continue to make content.
https://buymeacoffee.com/zenshell
Join our Discord
/ discord