Abusing Internet Facing Password Resets (and a 0-day)
ID: 0dc89d9c-383b-544b-a943-5d3ecd8a2c13
STIX ID: report--0dc89d9c-383b-544b-a943-5d3ecd8a2c13
Feed Name: TrustedSec blog
This report presents three penetration-test case studies of insecure password-reset implementations: (1) username enumeration enabling account lockout and denial-of-service/financial impact; (2) LDAP injection combined with weak security questions and OSINT allowing account matching, password resets, and exfiltration of plaintext SSNs; and (3) an ASP.NET ViewState misconfiguration that exposed security-question answers, enabling password reset, internal access, and eventual domain admin compromise. The author recommends input validation and hardening (prevent LDAP injection), rate limiting and careful lockout policies, server-side storage or encryption of sensitive state (or setting ViewStateEncryptionMode to Always), and rigorous testing and code review.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
