Skip to content
#

account-takeover

Here are 18 public repositories matching this topic...

mapAccountHijack is a tool designed to carry out a MAP Account hijack attack, which exploits the Message Access Profile (MAP) in Bluetooth Classic, enables the theft of MFA and OTPs leading to the successful hijacking of accounts on services that rely on SMS OTPs during login or recovery. Tool leaks phone numbers, emails, can send and retrieve SMS

  • Updated Feb 1, 2025
  • Python

Advanced security research lab on BOLA (CWE-285) and IDOR in RESTful architectures. Features a Flask-based API gateway and a Python-engineered exploit engine demonstrating Account Takeover (ATO) via JSON payload manipulation. Includes enterprise remediation strategies using cryptographically signed session claims and server-side authorization.

  • Updated Feb 25, 2026
  • Python

Improve this page

Add a description, image, and links to the account-takeover topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the account-takeover topic, visit your repo's landing page and select "manage topics."

Learn more