hunt-ato - Hunt account takeover paths and validate exploitability
Tests account-takeover paths across password resets, email changes, MFA, OAuth, sessions, JWTs, recovery flows, and chains with end-to-end impact validation.
Tags
Updated: 2026-10-08Capabilities
What this skill does
- Identify reset poisoning
- Test reset token leakage
- Test email change re-authentication
- Assess JWT trust boundaries
- Test OAuth redirect abuse
- Test recovery-question abuse
- Test SSO subdomain takeover
- Chain takeover primitives
- Validate takeover impact
Inputs
- Target application
- Test accounts A and B
- Password reset endpoints
- Email change endpoints
- MFA and OAuth endpoints
- Session and JWT tokens
- Controlled victim inbox
- Out-of-band callback server
- Candidate token lists
- DNS or cloud provider access
Outputs
- Account takeover validation result
- Captured reset tokens
- Captured OAuth codes or tokens
- Privileged endpoint responses
- Changed test-account credentials
- Account takeover severity
Requirements
- Authorized target access
- Permission to test both accounts
- HTTP testing client
- Browser with network inspection
- Out-of-band callback infrastructure
- DNS or cloud provider account for takeover testing
