Collected research
Paypal Manager Account Hijack
A chained attack on PayPal Manager: Burp Intruder enumerates valid vendor accounts by response length, a reused password-reset token bypasses the security question, and removing the Referer header completes the reset. Sending a spoofed X-Forwarded-For value then defeats the IP restriction screen, giving admin access to another merchant's account and customer data.
Record
- Researcher
- Mark Litchfield
- Published by
- securatary.com
- Format
- Whitepaper
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Mark Litchfield, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .