Skip to content

Normalization and Unicode attacks (password resets)

  1. Force the application to send the reset link to an attacker-controlled email address:
  2. Force the application to send a password reset link with a wrong target domain:

More examples: https://youtu.be/WCuPq-Aw714?si=w1mT-rwqIpPuRNCB&t=1070

Example domains:

  • sysliftërs.com
  • syslıfters.com