Account takeover (ATO)
SkillCommunicationSystematic account-takeover hunting, password reset, email change, session, and linking flaws that seize another user's account. Load on "ATO", password-reset/forgot flows, email-change, OTP/2FA, "login as", session handling. Signals: reset tokens, email-change without re-auth, OTP, magic links.
Use Account takeover (ATO) in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Account takeover (ATO) and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Account takeover (ATO) skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/web/web-account-takeover/SKILL.md and read by ahel’s review.
When it applies
Any flow that can grant control of another user's account: password reset, email change, session issuance, social/SSO linking, OTP/2FA. ATO is the highest-value web finding — hunt it deliberately.
Why it works
Auth flows have many moving parts (tokens, emails, sessions, second factors); a single weak link — a predictable reset token, a host-header-controlled reset link, an email change without re-auth, an OTP with no rate limit — hands over the account.
Method
- Password reset: token predictability/entropy, token not invalidated after use/expiry,
Host/X-Forwarded-Hostpoisoning the reset link (→ leak token to your domain), reset for another user by changing theemail/idparam, response leaking the token. - Email change: change to attacker email without password re-auth or without confirming the old address → then reset.
- OTP/2FA: no rate limit (brute — see
web-race-conditions), OTP reuse, response leaks the code, 2FA skippable by hitting the post-2FA endpoint directly, backup-code weaknesses. - Session: fixation, tokens not rotated on login/priv-change, JWT flaws (→
web-auth-jwt), long-lived "remember me" tokens. - SSO/linking: pre-account-takeover and
redirect_uritheft (→web-oauth).
Gotchas
- Use two accounts you own; prove takeover end-to-end (log in as the "victim" account you control).
- Host-header reset-poisoning needs the app to build the link from the header — test it explicitly.
- Chain small pieces (info leak → reset param) rather than expecting one silver bullet.
Verify success
You authenticate as another account without its legitimate credentials, demonstrated across two accounts you own.
References
PortSwigger auth labs; "Account takeover methodology" write-ups; OWASP WSTG (authentication).
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
web-account-takeover- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · jeremylongshore
The pick for Web (OWASP)owasp-security
Skill · davila7
The pick for Web (OWASP)slack-gif-creator
Skill · anthropics
More in Communicationerror-handling
Skill · affaan-m
More in Communicationemails
Skill · coreyhaines31
More in Communicationwait-what
Skill · mattpocock
More in Communication