Account takeover (ATO)
SkillCommunicationSystematic account-takeover hunting, password reset, email change, session, and linking flaws that seize another user's account. Load on "ATO", password-reset/forgot flows, email-change, OTP/2FA, "login as", session handling. Signals: reset tokens, email-change without re-auth, OTP, magic links.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Account takeover (ATO) skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/web/web-account-takeover/SKILL.md and read by ahel’s review.
When it applies
Any flow that can grant control of another user's account: password reset, email change, session issuance, social/SSO linking, OTP/2FA. ATO is the highest-value web finding — hunt it deliberately.
Why it works
Auth flows have many moving parts (tokens, emails, sessions, second factors); a single weak link — a predictable reset token, a host-header-controlled reset link, an email change without re-auth, an OTP with no rate limit — hands over the account.
Method
- Password reset: token predictability/entropy, token not invalidated after use/expiry,
Host/X-Forwarded-Hostpoisoning the reset link (→ leak token to your domain), reset for another user by changing theemail/idparam, response leaking the token. - Email change: change to attacker email without password re-auth or without confirming the old address → then reset.
- OTP/2FA: no rate limit (brute — see
web-race-conditions), OTP reuse, response leaks the code, 2FA skippable by hitting the post-2FA endpoint directly, backup-code weaknesses. - Session: fixation, tokens not rotated on login/priv-change, JWT flaws (→
web-auth-jwt), long-lived "remember me" tokens. - SSO/linking: pre-account-takeover and
redirect_uritheft (→web-oauth).
Gotchas
- Use two accounts you own; prove takeover end-to-end (log in as the "victim" account you control).
- Host-header reset-poisoning needs the app to build the link from the header — test it explicitly.
- Chain small pieces (info leak → reset param) rather than expecting one silver bullet.
Verify success
You authenticate as another account without its legitimate credentials, demonstrated across two accounts you own.
References
PortSwigger auth labs; "Account takeover methodology" write-ups; OWASP WSTG (authentication).
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
web-account-takeover- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · handsontable
The pick for End-to-end testingmstar-e2e
Skill · btspoony
The pick for End-to-end testingowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)slack-gif-creator
Skill · anthropics
More in Communicationerror-handling
Skill · affaan-m
More in Communication