Vulnerable Remember Password
Methodology
Black Box
Trigger the Passwordless / Remember Me Login
1
2
3
4
5
6
7
8
Clickjacking on Auto-Login Page
1
<iframe src="https://target.com/auto-login" style="opacity:0.1"></iframe>2
CSRF on Auto-Auth Flow
1
<img src="https://target.com/remembered-login-endpoint">2
White Box
Cheat Sheet
Last updated