Hack the Planet :)

Hello Hackers!

Today I am going to disclose my recent finding where I was able to takeover the user's account. So the target was planet.com as initially I was looking for some of the bugs in Google acquisitions :p

After Whois lookup and gathering some information from Crunchbase and Wiki, I came to know that it wasn't Google's acquisition but I still looked for vulnerabilities and found ACCOUNT TAKEOVER :)

Basically there was an IDOR vulnerability on their reset password link.

Check out the POC:



