This paper is designed to document an attack technique Sec-1 recently adopted during the course of their application assessments. The basic principal of this technique has existed for some time; however we hope this paper we will provide an insight of how a variation of the technique can be adopted to attack common forgotten password functionality within web applications.
The document is split into two sections. The first section covers the principals of the technique and the second is an attack case study against a commercial application.
Download: Buffer Truncation Abuse Paper