Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Amin Malekpour. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Amin Malekpour or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Ep. 11 – Account Takeover, Token Misuse, and Deserialization RCE: When Trust Goes Wrong

17:15
 
Share
 

Manage episode 496330953 series 3643227
Content provided by Amin Malekpour. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Amin Malekpour or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

One flawed password reset. One shared session token. One dangerous object.

In Episode 11 of Hacked & Secured: Pentest Exploits & Mitigations, we break down three real-world vulnerabilities where trust between systems and users broke down—with serious consequences.

  • Account Takeover via Forgot Password – A predictable ID and exposed tokens let attackers reset passwords without access to email.
  • Session Hijack in OTP Login – A logic flaw in how login tokens were handled allowed full account access with just a user ID.
  • Remote Code Execution via Java Deserialization – A community-contributed finding where an exposed service deserialized untrusted input, leading to code execution.

These aren’t complex chains. They’re common mistakes with big impact—and important lessons for developers, security teams, and testers.

Chapters:

00:00 - INTRO

00:59 - FINDING #1 - Account Takeover via Forgot Password

06:26 - FINDING #2 - Shared Session Token in SMS Login Flow

10:39 - FINDING #3 - Java Deserialisation to Remote Code Execution

16:13 - OUTRO
Want your pentest discovery featured? Submit your creative findings through the Google Form in the episode description, and we might showcase your finding in an upcoming episode!
🌍 Follow & Connect → LinkedIn, YouTube, Twitter, Instagram
📩 Submit Your Pentest Findings https://forms.gle/7pPwjdaWnGYpQcA6A
📧 Feedback? Email Us [email protected]
🔗 Podcast Website → Website Link

  continue reading

Chapters

1. INTRO (00:00:00)

2. FINDING #1 - Account Takeover via Forgot Password (00:00:59)

3. FINDING #2 - Shared Session Token in SMS Login Flow (00:06:26)

4. FINDING #3 - Java Deserialisation to Remote Code Execution (00:10:39)

5. OUTRO (00:16:13)

12 episodes

Artwork
iconShare
 
Manage episode 496330953 series 3643227
Content provided by Amin Malekpour. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Amin Malekpour or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

One flawed password reset. One shared session token. One dangerous object.

In Episode 11 of Hacked & Secured: Pentest Exploits & Mitigations, we break down three real-world vulnerabilities where trust between systems and users broke down—with serious consequences.

  • Account Takeover via Forgot Password – A predictable ID and exposed tokens let attackers reset passwords without access to email.
  • Session Hijack in OTP Login – A logic flaw in how login tokens were handled allowed full account access with just a user ID.
  • Remote Code Execution via Java Deserialization – A community-contributed finding where an exposed service deserialized untrusted input, leading to code execution.

These aren’t complex chains. They’re common mistakes with big impact—and important lessons for developers, security teams, and testers.

Chapters:

00:00 - INTRO

00:59 - FINDING #1 - Account Takeover via Forgot Password

06:26 - FINDING #2 - Shared Session Token in SMS Login Flow

10:39 - FINDING #3 - Java Deserialisation to Remote Code Execution

16:13 - OUTRO
Want your pentest discovery featured? Submit your creative findings through the Google Form in the episode description, and we might showcase your finding in an upcoming episode!
🌍 Follow & Connect → LinkedIn, YouTube, Twitter, Instagram
📩 Submit Your Pentest Findings https://forms.gle/7pPwjdaWnGYpQcA6A
📧 Feedback? Email Us [email protected]
🔗 Podcast Website → Website Link

  continue reading

Chapters

1. INTRO (00:00:00)

2. FINDING #1 - Account Takeover via Forgot Password (00:00:59)

3. FINDING #2 - Shared Session Token in SMS Login Flow (00:06:26)

4. FINDING #3 - Java Deserialisation to Remote Code Execution (00:10:39)

5. OUTRO (00:16:13)

12 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play