@declanmidd: 🚨 I Found a Password Reset Vulnerability! | VulNyx CTF (University) In this clip from my previous livestream, I discovered an information disclosure vulnerability during an authorized VulNyx CTF. While analyzing the password reset functionality with Burp Suite, I noticed the server was returning the generated recovery code directly in the HTTP response a serious security design flaw if implemented in a real application. 🛡️ This clip is for cybersecurity education and demonstrates why sensitive values should never be exposed to the client during password recovery workflows. ⚠️ Disclaimer: All testing was performed in an authorized CTF/lab environment for educational purposes only. Never perform security testing on systems without explicit permission. #CyberSecurity #EthicalHacking #BurpSuite #WebSecurity #InfoSec
The Site itself leaks the new pass, you do not need burp Suite to See what request got sended, and the request content
2026-07-05 12:53:32
0
Jeroen🤪🐻🦋😝 :
That would be so stupid if this was real. This is fake
2026-07-05 18:15:57
6
Acrexia07 :
that's why we don't expose password field on response ✨
2026-07-04 09:22:43
7
mahmoud :
ctf level 0 or maybe -1
2026-07-07 13:14:28
13
— Kosei :
if resetting password requires any third party verification or authentication its not that big deal since you cant randomly reset password also that response only visible on your Device/computer also if you try to spoof the api its not that easy when it requires third party verification or authentication but still that method is not recommended
2026-07-24 14:20:00
0
Christian Milan :
But who’s json?
2026-07-08 15:28:42
0
SA'V7N :
how to learn it with you?
2026-07-27 02:06:19
0
⚡ZeeZ⚡ :
BURP
2026-07-23 00:42:18
0
Nguyễn Hoàng Quân :
Does it mean that if a random person requests a password reset using your email address, you'll receive the new password by email, while the recovery code from the request is sent back to that person??
2026-07-06 16:07:34
0
SA :
I guess this was vibe coded 😂
2026-07-05 17:20:15
4
QalbEcho :
Burp suit
2026-07-25 13:26:22
0
Abatimuhar :
I usually do it with mises and additional extensions because I use Android
2026-07-09 17:23:10
0
user9793799717115 :
burpsuite
2026-07-16 10:49:26
0
GD-PLAYER-GAMER-ROBLOX :
W
2026-07-27 13:39:02
0
indigo :
Burp
2026-07-04 02:55:08
5
Pirate King :
buuuuuurp
2026-07-04 17:00:02
0
ếch :
good
2026-07-04 13:29:52
0
mama_boy677 :
Burp pro🔥
2026-07-04 13:50:58
1
่ :
burp
2026-07-04 09:45:25
1
yurhu :
BAC
2026-07-04 12:30:52
0
To see more videos from user @declanmidd, please go to the Tikwm
homepage.