Web Hard
3 min read
XSS to Account Takeover - Real World Example
How we chained XSS with CSRF to achieve full account takeover on a production system
by havoc 2025-11-02
CTF Team. Reverse Engineers. Innovators.
Decrypt. Dissect. Dominate.
51l3nt_br34ch// is a cybersecurity collective specializing in Capture The Flag competitions and penetration testing. We dissect vulnerabilities, reverse engineer complex systems, and push the boundaries of what's possible in offensive security. Our mission is to share knowledge through detailed technical writeups and establish ourselves as thought leaders in the cybersecurity community.
How we chained XSS with CSRF to achieve full account takeover on a production system
Bypassing NX protection using return-to-libc technique
Breaking RSA encryption by factoring small primes