This lesson is for subscribers
You've completed the free preview. Subscribe to unlock every lesson in every course.
Manipulating Host headers in password reset flows to redirect tokens to attacker-controlled domains and hijack accounts.
You've completed the free preview. Subscribe to unlock every lesson in every course.