---
title: Stealing Password Reset Tokens for Fun and Profit - Cyber Security Consultants - Alchemy
description: When adding a “Password Reset” function to your application it is especially important to ensure this has the same security considerations as any other cri
image: https://www.alchemysec.com.au/hubfs/Imported_Blog_Media/Hacker-white-background.png
---

[Go Back Up](https://www.alchemysec.com.au/blog/stealing-password-reset-tokens-for-fun-and-profit#top)

[Skip to Content](https://www.alchemysec.com.au/blog/stealing-password-reset-tokens-for-fun-and-profit#body)

**University of Sydney Code Library Breach:** Disclosed 18 Dec, 2025

Personal details of about 27,500 current and former staff exposed.

18 Dec 2025 - Syd Uni breached

[Read more](https://www.sydney.edu.au/news-opinion/news/2025/12/18/notification-of-cyber-and-data-breach.html)

[![Alchemy\_Security\_Consulting\_Logo\_B2\_Cropped\_White\_400](https://www.alchemysec.com.au/hs-fs/hubfs/Alchemy_Security_Consulting_Logo_B2_Cropped_White_400.png?width=200&name=Alchemy_Security_Consulting_Logo_B2_Cropped_White_400.png)](https://www.alchemysec.com.au/)

- Offensive Security
- Defensive Security
- Managed Services
- Company
- Resources

[Have you been breached?](https://www.alchemysec.com.au/breached) [Book a consult](https://www.alchemysec.com.au/contact)

[Offensive Security](https://www.alchemysec.com.au/services/offensive) [Penetration Testing](https://www.alchemysec.com.au/services/offensive/pentest) [Red Teaming](https://www.alchemysec.com.au/services/offensive/red-teaming) [Adversary Simulation](https://www.alchemysec.com.au/services/offensive/adversary-simulation) [Purple Teaming](https://www.alchemysec.com.au/services/offensive/purple-teaming)

[Defensive Security](https://www.alchemysec.com.au/services/defensive) [Incident Response](https://www.alchemysec.com.au/breached) [SIEM, Logging & Detection Engineering](https://www.alchemysec.com.au/services/defensive/siem-logging)

[Managed Services](https://www.alchemysec.com.au/services/managed) [Managed Detection & Response](https://www.alchemysec.com.au/services/managed/mdr) [Managed SOC](https://www.alchemysec.com.au/services/managed/soc) [Continuous Threat Emulation](https://www.alchemysec.com.au/services/managed/continuous-threat-emulation)

[About Us](https://www.alchemysec.com.au/about) [Contact Us](https://www.alchemysec.com.au/contact)

[Blog](https://www.alchemysec.com.au/blog)

- Offensive Security
  
  [Offensive Security](https://www.alchemysec.com.au/services/offensive) [Penetration Testing](https://www.alchemysec.com.au/services/offensive/pentest) [Red Teaming](https://www.alchemysec.com.au/services/offensive/red-teaming) [Adversary Simulation](https://www.alchemysec.com.au/services/offensive/adversary-simulation) [Purple Teaming](https://www.alchemysec.com.au/services/offensive/purple-teaming)
- Defensive Security
  
  [Defensive Security](https://www.alchemysec.com.au/services/defensive) [Incident Response](https://www.alchemysec.com.au/breached) [SIEM, Logging & Detection Engineering](https://www.alchemysec.com.au/services/defensive/siem-logging)
- Managed Services
  
  [Managed Services](https://www.alchemysec.com.au/services/managed) [Managed Detection & Response](https://www.alchemysec.com.au/services/managed/mdr) [Managed SOC](https://www.alchemysec.com.au/services/managed/soc) [Continuous Threat Emulation](https://www.alchemysec.com.au/services/managed/continuous-threat-emulation)
- Company
  
  [About Us](https://www.alchemysec.com.au/about) [Contact Us](https://www.alchemysec.com.au/contact)
- Resources
  
  [Blog](https://www.alchemysec.com.au/blog)

[Have you been breached?](https://www.alchemysec.com.au/breached) [Book a consult](https://www.alchemysec.com.au/contact)

# Stealing Password Reset Tokens for Fun and Profit

[Blog](https://www.alchemysec.com.au/blog/tag/blog) [Threat Emulation](https://www.alchemysec.com.au/blog/tag/threat-emulation) 28 December 2020 [Alex](https://www.alchemysec.com.au/blog/author/alex) 3 min read

![](https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Hacker-white-background.png?width=1000&name=Hacker-white-background.png)

<https://twitter.com/intent/tweet/?text=Stealing+Password+Reset+Tokens+for+Fun+and+Profit+-+Cyber+Security+Consultants+-+Alchemy&url=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fstealing-password-reset-tokens-for-fun-and-profit> <https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fstealing-password-reset-tokens-for-fun-and-profit> <https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fstealing-password-reset-tokens-for-fun-and-profit> [mailto:?subject=Stealing%20Password%20Reset%20Tokens%20for%20Fun%20and%20Profit%20-%20Cyber%20Security%20Consultants%20-%20Alchemy&body=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fstealing-password-reset-tokens-for-fun-and-profit](mailto:?subject=Stealing%20Password%20Reset%20Tokens%20for%20Fun%20and%20Profit%20-%20Cyber%20Security%20Consultants%20-%20Alchemy&body=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fstealing-password-reset-tokens-for-fun-and-profit)

When adding a “Password Reset” function to your application it is especially important to ensure this has the same security considerations as any other critical function within the application. Due to the nature of resetting a user’s password, along with many security considerations being overlooked, it is not uncommon for attackers to spend extra time trying to bend these types of functions to their will to try and gain unauthorised access.

There are some key considerations that must take place when implementing this functionality to ensure it cannot be abused by attackers:

- it should essentially be impossible for an attacker to obtain in any manner a password reset token for another user,
- tokens must have a limited time span and be invalidated upon use,
- tokens must be authorised to only perform a password reset.

Let’s take a look in the case of an application Alchemy Security tested recently.

**Problem one – static password reset tokens**

For each user a password reset token was created at time of account creation and stored in the database as part of the credentials. This meant the account had a single reset token valid for the lifetime of the account, independent of how many times the user forgot their password.

As the token was not invalidated after a period of time or once used, this meant that even if the legitimate user reset their password, an attacker still had access to the token and in turn the account, another weakness detailed in problem two. It also appeared likely that the token could not be invalidated without deleting and re-creating the account.

The token was returned in a ‘HTTP 200 OK’ response from the API endpoint, so while not visible within the web page itself, was still easily obtainable by an attacker simply using an interception proxy such as Burp Suite. This meant that an attacker could easily write a script to test a list of usernames and obtain the token for each by parsing the resulting response.

To make matters worse, all of the above actions do not require any user authentication. Allowing an un-authenticated attacker to easily enumerate both usernames and their associated reset tokens without restriction or valid credentials.

![](https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/leaked-token1.png?width=941&height=172&name=leaked-token1.png)

 Leaked password reset token.

**Problem two – excessive token permissions & incorrect authorisation checks**

The biggest problem was the token itself had excessive permissions and was able to perform almost any action for which the user already had permissions. For example, the token could be used to update the user’s profile (which then leaked the user’s password hash, another big issue!) or perform search functions to access data for which the user had access to.

These two issues meant that the application was prone to two critical security issues:

1. Account takeovers: An attacker able to obtain a reset token now had the ability to change a user’s email address associated with the account and perform an actual password reset (among other changes).
2. Application takeover: If an attacker targeted an admin account, they could essentially take full control of the application, locking out other administrator accounts and accessing all data within the application. Alternately, they could make changes to any other account of their choice, including escalating privileges of a low privileged account they already had access to.

![](https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/leaked-token2.png?width=941&height=164&name=leaked-token2.png)

 Stealing an admin password reset token.

![](https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/leaked-token3.png?width=941&height=514&name=leaked-token3.png)

 Escalating privileges using stolen token.

These issues can be easily be avoided in the following manner:

- ensure reset tokens are only created once a user runs the “password reset” function,
- tokens must only be provided to the user requesting the reset via an email address previously validated and connected to the account and not returned via the web application front end,
- tokens must only be authorised to perform a reset and not have permissions for any other purpose,
- tokens must not be easily guessed, predictable or able to be brute forced.

## Alex

## Ready to Transform your Business with Little Effort Using Brightlane?

[Register Now](https://www.example.com)

You May Like These

## Related Articles

![](https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/text-figure1-01-1024x571.jpg?width=700&name=text-figure1-01-1024x571.jpg)

### [MITRE ATT&CK Framework Primer](https://www.alchemysec.com.au/blog/mitre-attck-framework-primer)

![](https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/chris-yang-1tnS_BVy9Jk-unsplash-1024x683-1.jpg?width=700&name=chris-yang-1tnS_BVy9Jk-unsplash-1024x683-1.jpg)

### [OSINT for Penetration Testers](https://www.alchemysec.com.au/blog/osint-for-penetration-testers)

![](https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/envelope-01-1024x572.jpg?width=700&name=envelope-01-1024x572.jpg)

### [Please Sign Here - Why NTLM Relaying Is Still a Risk in 2021](https://www.alchemysec.com.au/blog/please-sign-here-why-ntlm-relaying-is-still-a-risk-in-2021)

---

![Alchemy Security Consulting](https://www.alchemysec.com.au/hubfs/Images/Logos/Alchemy/Alchemy_Security_Consulting_Logo_B2_Cropped_White_350.png)

 Offensive, defensive and managed security expertise to help you understand your exposure, strengthen your defences and validate improvement.

#### Get In Touch

##### Location

 30 Pirie St, Adelaide, South Australia 5000

##### Contact

###### Phone :

[1300 792 870](tel:+611300792870)

###### Email :

[sales@alchemysec.com.au](mailto:sales@alchemysec.com.au)

#### Services

- [Penetration Testing](https://www.alchemysec.com.au/services/offensive/pentest)
- [Red Teaming](https://www.alchemysec.com.au/services/offensive/red-teaming)
- [Adversary Simulation](https://www.alchemysec.com.au/services/offensive/adversary-simulation)
- [Purple Teaming](https://www.alchemysec.com.au/services/offensive/purple-teaming)
- [Incident Response](https://www.alchemysec.com.au/breached)
- [SIEM, Logging & Detection Engineering](https://www.alchemysec.com.au/services/defensive/siem-logging)
- [Managed Detection & Response](https://www.alchemysec.com.au/services/managed/mdr)
- [Managed SOC](https://www.alchemysec.com.au/services/managed/soc)
- [Continuous Threat Emulation](https://www.alchemysec.com.au/services/managed/continuous-threat-emulation)

#### Company

- [About Us](https://www.alchemysec.com.au/about)
- [Blog](https://www.alchemysec.com.au/blog)
- [Contact](https://www.alchemysec.com.au/contact)
- [Book a Consult](https://www.alchemysec.com.au/contact)
- [Privacy Policy](https://www.alchemysec.com.au/privacy-policy)

© Alchemy Security. All rights reserved | [Privacy Policy](https://www.alchemysec.com.au/privacy-policy)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Alex",
    "url" : "https://www.alchemysec.com.au/blog/author/alex"
  },
  "dateModified" : "2026-09-30T10:34:34.372Z",
  "datePublished" : "2020-12-28T05:00:00.000Z",
  "headline" : "Stealing Password Reset Tokens for Fun and Profit - Cyber Security Consultants - Alchemy",
  "image" : [ "https://www.alchemysec.com.au/hubfs/Imported_Blog_Media/Hacker-white-background.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.alchemysec.com.au/blog/stealing-password-reset-tokens-for-fun-and-profit",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.alchemysec.com.au/hubfs/Alchemy_Security_Consulting_Logo_B2_Cropped_White_300.png"
    }
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://alchemysec.com.au/#organization",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "AU",
    "addressLocality" : "Adelaide",
    "addressRegion" : "SA",
    "postalCode" : "5000",
    "streetAddress" : "30 Pirie St"
  },
  "description" : "Cybersecurity consultancy providing offensive security, defensive security and managed security services.",
  "email" : "sales@alchemysec.com.au",
  "name" : "Alchemy Security Consulting",
  "telephone" : "+611300792870",
  "url" : "https://alchemysec.com.au/"
}
```