Collected research
Puny-Code, 0-Click Account Takeover
Explains how database collation can equate distinct email spellings while message delivery preserves their difference. Reset and OAuth examples map the wrong identity to a victim account; SQL probes, a safe WordPress stored-address counterexample and a testbed distinguish the database comparison from the address ultimately used for delivery.
Record
- Researcher
- Yashar Shahinzadeh and Amirmohammad Safari
- Published by
- Voorivex
- Date
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Yashar Shahinzadeh and Amirmohammad Safari, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .