Last updated 4 years ago
I was testing for ATO via reset function . Tried all method but no success. My friend gave me tip to add double Host in request while requesting password Host: Host: Boom it worked
Password reset poisoning -