← back to room
Boss
VaultMail — Reset
Scenario
VaultMail reset emails honour X-Forwarded-Host when building links, and reset tokens follow a guessable pattern. You know the victim username but they never click phishing links. Complete account claim without user interaction.
Your approach
- Request a reset for the victim with a poisoned forwarded host header.
- Derive or read the predictable token format from lab hints.
- Visit the claim endpoint with the victim token while hosting the evil reset domain if needed.
- Confirm takeover and read the boss flag.
- Submit the zero-click ATO flag.
1 Poison reset
2 Predict / steal token
3 Claim account
The reset email builds its link from a forwarded host header when present. Tokens follow a predictable pattern based on the username.