Blog | Spandan Pokhrel
  • Home
  • About
Sign in Subscribe

Spandan Pokhrel

One-Click account takeover.

When testing for vulnerabilities, testing buttons like "Connect with Google" or "Connect with Facebook" that integrate third-party applications may seem quite straightforward. Typically, these actions send a request to the respective third-party server, which then returns an authorization code. This code is included in an HTTP
01 Sep 2026 3 min read

CSRF on Password Reset Link leading to account takeover.

Have you ever thought of testing for CSRF vulnerability on a password reset link? You might not have, because we generally believe that it is not possible, as the password reset link itself contains a reset token which acts as an alternative for a CSRF token. I, too, once shared
01 Sep 2026 3 min read
Page 1 of 1
Blog | Spandan Pokhrel © 2026
  • Sign up
Powered by Ghost