Web Hack List

Collected research

Puny-Code, 0-Click Account Takeover

Explains how database collation can equate distinct email spellings while message delivery preserves their difference. Reset and OAuth examples map the wrong identity to a victim account; SQL probes, a safe WordPress stored-address counterexample and a testbed distinguish the database comparison from the address ultimately used for delivery.

Record

Researcher
Yashar Shahinzadeh and Amirmohammad Safari
Published by
Voorivex
Date
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Yashar Shahinzadeh and Amirmohammad Safari, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .