Skip to content
#

account-takeover

Here are 62 public repositories matching this topic...

mapAccountHijack is a tool designed to carry out a MAP Account hijack attack, which exploits the Message Access Profile (MAP) in Bluetooth Classic, enables the theft of MFA and OTPs leading to the successful hijacking of accounts on services that rely on SMS OTPs during login or recovery. Tool leaks phone numbers, emails, can send and retrieve SMS

  • Updated Feb 1, 2025
  • Python
Web-Vulnerabilities

27 hands-on web vulnerability playbooks for bug bounty hunters, pentesters, and red teamers. Covers IDOR, SSRF, XSS, RCE, ATO, 2FA bypass, OAuth, JWT, file upload, business logic, rate limit, CSRF, SQLi, and more- with payloads and bypass tables.

  • Updated Jun 14, 2026

Deduce — independent third-party profile of a public API surface, by API Evangelist. Deduce is a New York City-based identity intelligence and fraud-prevention company focused on detecting stolen and synthetic identities, including the rapidly growing class of AI-generated identities used to bypass traditional Know Your Customer and onboarding cont

  • Updated Sep 4, 2026

The application contained a broken password reset implementation that failed to properly validate the relationship between the password reset request and the intended user account. By manipulating user-controlled parameters during the reset process, it was possible to reset another user's password without proper authorization.

  • Updated Jul 4, 2026

Add this topic to your repo

To associate your repository with the account-takeover topic, visit your repo's landing page and select "manage topics."

Learn more