@declanmidd: 😳 I Found a Password Reset Flaw in a CTF… In this clip from my previous livestream, I was testing an authorized VulNyx CTF using Burp Suite when I noticed something unusual. Normally, when you request a password reset, the recovery code should remain secret and only be delivered securely to the account owner. Instead, the web server returned the generated recovery code directly in its HTTP response. If this happened in a real-world application, it could expose sensitive password reset information and weaken the security of the account recovery process. This type of issue is commonly known as an information disclosure vulnerability because the application reveals data that should never be exposed to the client. ⚠️ Disclaimer: This demonstration was performed in an authorized CTF/lab environment for cybersecurity education only. Never test systems without explicit permission. #C#CyberSecurityE#EthicalHackingB#BurpSuiteW#WebSecurityI#InfoSec#CTF
Comment: “BURP” if you spotted the flaw before I explained it! 👀
2026-07-04 03:13:34
2
insom.ai :
Password reset is still the most underrated attack surface. In real apps the same class of bug shows up as host header poisoning on the reset link or tokens that never expire. Great that you are practicing it in CTFs, it transfers directly
2026-08-18 10:21:28
1
Gailo Willy :
bro teach me
2026-07-05 06:44:53
2
:
BURPPPPPP
2026-07-04 12:39:24
1
To see more videos from user @declanmidd, please go to the Tikwm
homepage.