註冊並分享邀請連結,可獲得影片播放與邀請獎勵。

IT Guy
@T3chFalcon
Privacy Researcher. Check out my Articles 🥺. DM For Collabs & Partnerships. Founder @PhishCore - Human risk intelligence & Phishing simulation platform.
加入 November 2022
512 正在關注    45.5K 粉絲
YES. password reset doesn't kill an active session by default. most platforms don't force logout on every device unless you explicitly hit "log out everywhere." so if an attacker's session cookie is still alive when you change your password, they're still in. password reset also doesn't touch: oauth grants — third-party apps you approved keep their tokens mail forwarding rules — silently BCC'ing every email you get delegate access — someone else added as a mailbox admin app-specific passwords — bypass your main login entirely mfa backup methods — a phone number or recovery email they added The fix is to revoke all sessions, audit connected apps, check forwarding rules, and review recovery methods.
顯示更多
Can an attacker stay inside your account after you change your password?
0
6
541
89
轉發到社區