The "Forgot password?" feature and how DNS vulnerabilities may allow the takeover of user accounts

Discussion in 'other security issues & news' started by guest, Jul 24, 2021.

  1. guest

    guest Guest

    Dozens of web apps vulnerable to DNS cache poisoning via ‘forgot password’ feature
    Of 146 tested, two applications were vulnerable to Kaminsky attacks, and 62 to IP fragmentation attacks
    July 23, 2021

    https://portswigger.net/daily-swig/...s-cache-poisoning-via-forgot-password-feature
    Forgot password? Taking over user accounts Kaminsky style
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice