Account Takeover due to Improper Rate-Limit/Anti-Automation Checks
Account Takeover due to Weak Security Policies
Account Takeover by utilizing Sensitive Data Exposure
Account Takeover by XSS
Misc. Methods
Response Body Manipulation
Status Code Manipulation
Parameter Pollution
Mass Assignment
Token Forging
More Details on These Attack Vectors can be found at:
https://github.com/harsh-bothra/SecurityExplained/blob/main/resources/account-takeovers-methodology.md
MindMap Created By:
Harsh Bothra
(Twitter: @harshbothra_)