Yes. The Program Owner is correct at their place.
2021-01-07 19:12:18 Author: medium.com(查看原文) 阅读量:214 收藏

Yes. The Program Owner is correct at their place. The issue described in this blog talks about Performing Account Takeover due to weak and guessable cryptography. The alias emails are used for the detection and confirmation of the vulnerability. In my case, I do not need any user interaction or access to the victim's email. In this issue, I can use your email say [email protected] and if your account exists, I can takeover it. I hope you understand it now.


文章来源: https://medium.com/@hbothra22/yes-the-program-owner-is-correct-at-their-place-c366200b8b14?source=rss-54fa249211d2------2
如有侵权请联系:admin#unsafe.sh