<?xml version="1.0"?>
<oembed><version>1.0</version><provider_name>S&#xE9;curiser votre site</provider_name><provider_url>https://www.searchevolution.com/security</provider_url><author_name>Germain</author_name><author_url>https://www.searchevolution.com/security/author/germain/</author_url><title>Account takeover - S&#xE9;curiser votre site</title><type>rich</type><width>600</width><height>338</height><html>&lt;blockquote class="wp-embedded-content" data-secret="EPf3FLPEUT"&gt;&lt;a href="https://www.searchevolution.com/security/2022/11/07/account-takeover/"&gt;Account takeover&lt;/a&gt;&lt;/blockquote&gt;&lt;iframe sandbox="allow-scripts" security="restricted" src="https://www.searchevolution.com/security/2022/11/07/account-takeover/embed/#?secret=EPf3FLPEUT" width="600" height="338" title="&laquo; Account takeover &raquo; &#x2014; S&#xE9;curiser votre site" data-secret="EPf3FLPEUT" frameborder="0" marginwidth="0" marginheight="0" scrolling="no" class="wp-embedded-content"&gt;&lt;/iframe&gt;&lt;script type="text/javascript"&gt;
/* &lt;![CDATA[ */
/*! This file is auto-generated */
!function(d,l){"use strict";l.querySelector&amp;&amp;d.addEventListener&amp;&amp;"undefined"!=typeof URL&amp;&amp;(d.wp=d.wp||{},d.wp.receiveEmbedMessage||(d.wp.receiveEmbedMessage=function(e){var t=e.data;if((t||t.secret||t.message||t.value)&amp;&amp;!/[^a-zA-Z0-9]/.test(t.secret)){for(var s,r,n,a=l.querySelectorAll('iframe[data-secret="'+t.secret+'"]'),o=l.querySelectorAll('blockquote[data-secret="'+t.secret+'"]'),c=new RegExp("^https?:$","i"),i=0;i&lt;o.length;i++)o[i].style.display="none";for(i=0;i&lt;a.length;i++)s=a[i],e.source===s.contentWindow&amp;&amp;(s.removeAttribute("style"),"height"===t.message?(1e3&lt;(r=parseInt(t.value,10))?r=1e3:~~r&lt;200&amp;&amp;(r=200),s.height=r):"link"===t.message&amp;&amp;(r=new URL(s.getAttribute("src")),n=new URL(t.value),c.test(n.protocol))&amp;&amp;n.host===r.host&amp;&amp;l.activeElement===s&amp;&amp;(d.top.location.href=t.value))}},d.addEventListener("message",d.wp.receiveEmbedMessage,!1),l.addEventListener("DOMContentLoaded",function(){for(var e,t,s=l.querySelectorAll("iframe.wp-embedded-content"),r=0;r&lt;s.length;r++)(t=(e=s[r]).getAttribute("data-secret"))||(t=Math.random().toString(36).substring(2,12),e.src+="#?secret="+t,e.setAttribute("data-secret",t)),e.contentWindow.postMessage({message:"ready",secret:t},"*")},!1)))}(window,document);
/* ]]&gt; */
&lt;/script&gt;
</html><description>Voici quelques techniques qui permettent de v&#xE9;rifier si la s&#xE9;curit&#xE9; pour la l&#x2019;authentification sur votre service est ad&#xE9;quate Account Takeover via IDOR in Password Reset Account Takeover by Password Reset Poisoning Acoount Takeover via IDOR (Post Authentication) Account Takeover via CSRF Account Takeover by Broken Cryptography Account Takeover by OAuth Misconfiguration Pre-Authentication Account Takeover Account Takeover due to Improper Rate-Limit/Anti-Automation Checks Account Takeover by XSS Account Takeover by utilizing Sensitive Data Exposure Account Takeover due to Weak Security Policies Autres techniques pour prendre possession d&#x2019;un compte Response Body Manipulation Status Code Manipulation Parameter Pollution Mass Assignment Token Forging Autres resources</description></oembed>
