Web Hack List

Collected research

Paypal Manager Account Hijack

A chained attack on PayPal Manager: Burp Intruder enumerates valid vendor accounts by response length, a reused password-reset token bypasses the security question, and removing the Referer header completes the reset. Sending a spoofed X-Forwarded-For value then defeats the IP restriction screen, giving admin access to another merchant's account and customer data.

Record

Researcher
Mark Litchfield
Published by
securatary.com
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mark Litchfield, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .