Skip to content

Commit 5afabe9

Browse files
authored
Delete username enumeration section from account-takeover.md
Removed section on username enumeration via recovery answers, including example command.
1 parent d418cff commit 5afabe9

File tree

1 file changed

+0
-12
lines changed

1 file changed

+0
-12
lines changed

src/pentesting-web/account-takeover.md

Lines changed: 0 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -97,17 +97,6 @@ username=admin_ef01cab31aa&new_answer1=A&new_answer2=B&new_answer3=C
9797

9898
Anything gated by the victim's `$_SESSION` context (admin dashboards, dangerous stream-wrapper features, etc.) is now exposed without touching the real answers.
9999

100-
### Username enumeration via recovery answers
101-
Many security-question portals leak whether a username exists via differential messaging (e.g., only nonexistent users return `User not found.`). Send a constant trio of bogus answers and fuzz the username list, filtering out responses containing the "not found" string:
102-
103-
```bash
104-
ffuf -d 'username=FUZZ&answer1=x&answer2=x&answer3=x' \
105-
-u http://file.era.htb/security_login.php \
106-
-H 'Content-Type: application/x-www-form-urlencoded' \
107-
-fr 'User not found.' \
108-
-w /opt/SecLists/Usernames/Names/names.txt
109-
```
110-
111100
Enumerated usernames can then be targeted via the overwrite technique above or reused against ancillary services (FTP/SSH password spraying).
112101

113102
## **Response Manipulation**
@@ -164,7 +153,6 @@ With the new login, although different cookies might be generated the old ones b
164153

165154
- [https://infosecwriteups.com/firing-8-account-takeover-methods-77e892099050](https://infosecwriteups.com/firing-8-account-takeover-methods-77e892099050)
166155
- [https://dynnyd20.medium.com/one-click-account-take-over-e500929656ea](https://dynnyd20.medium.com/one-click-account-take-over-e500929656ea)
167-
168156
- [0xdf – HTB Era: security-question IDOR & username oracle](https://0xdf.gitlab.io/2025/11/29/htb-era.html)
169157
{{#include ../banners/hacktricks-training.md}}
170158

0 commit comments

Comments
 (0)