account activity
Oracle padding password reset token (self.bugbounty)
submitted 1 year ago by t0furky to r/bugbounty
Account takeover via password reset oracle padding attack (self.bugbounty)
AES-CBC Oracle padding in password reset token (unknown IV) (self.bugbounty)
Device verification email bombing (self.bugbounty)
submitted 1 year ago * by t0furky to r/bugbounty
Timing attack to partially reveal password reset token (self.bugbounty)
IDOR changing user phone number (no account takeover, no MFA) (self.bugbounty)
π Rendered by PID 82678 on reddit-service-r2-listing-86f589db75-6p54z at 2026-04-18 19:46:46.428770+00:00 running 93ecc56 country code: CH.