Modern Web Firewall: stop account takeovers, weak passwords, cloud IPs, DoS attacks, disposable emails
-
Updated
Aug 1, 2022 - Java
Modern Web Firewall: stop account takeovers, weak passwords, cloud IPs, DoS attacks, disposable emails
mapAccountHijack is a tool designed to carry out a MAP Account hijack attack, which exploits the Message Access Profile (MAP) in Bluetooth Classic, enables the theft of MFA and OTPs leading to the successful hijacking of accounts on services that rely on SMS OTPs during login or recovery. Tool leaks phone numbers, emails, can send and retrieve SMS
Exploit for KeyCloak CVE-2026-18963
Welcome to the world of FingerprintJS open source software.
Instagram Penetration Testing and 2FA Detection
Go tool that detects which email addresses have domains which are able to be registered
🔴 CVE-2026-22794 - Appsmith Password Reset Account Takeover via Origin Header Injection | PoC Exploit + Nuclei Template
Analyse et modélisation d’un système de détection de fraude (Account Takeover) pour repérer les connexions suspectes et comportements anormaux.
27 hands-on web vulnerability playbooks for bug bounty hunters, pentesters, and red teamers. Covers IDOR, SSRF, XSS, RCE, ATO, 2FA bypass, OAuth, JWT, file upload, business logic, rate limit, CSRF, SQLi, and more- with payloads and bypass tables.
CVE-2026-40487 - Postiz <= 2.21.5 - Arbitrary File Upload via MIME-Type Spoofing → Stored XSS → Account Takeover
Software that blocks account hijacking attacks.
Xboard / V2Board Unauth Account Takeover - Magic Link Token Leak (CVE-2026-39912)
AI-based Early Warning System for Account Takeover (ATO) Detection using Machine Learning and Cybersecurity Analytics.
Recovery and containment guide for hacked WhatsApp, Instagram, Google, and social-media accounts.
Multi-vendor login risk engine (ThreatMetrix + BioCatch + LexisNexis): XGBoost ATO scoring, SHAP governance, and a threshold-tunable Allow/MFA/Block policy layer.
Top Account Takeover Protection 🌟 Star if you like it! 🌟
Deduce — independent third-party profile of a public API surface, by API Evangelist. Deduce is a New York City-based identity intelligence and fraud-prevention company focused on detecting stolen and synthetic identities, including the rapidly growing class of AI-generated identities used to bypass traditional Know Your Customer and onboarding cont
The application contained a broken password reset implementation that failed to properly validate the relationship between the password reset request and the intended user account. By manipulating user-controlled parameters during the reset process, it was possible to reset another user's password without proper authorization.
Risk-based emergency transaction lock framework for compromised accounts and fraud prevention.
Official Python client for Kaidn, the fraud and abuse scoring API. Score a signup, login or checkout and get allow/review/block with the reasons. Zero dependencies.
To associate your repository with the account-takeover topic, visit your repo's landing page and select "manage topics."