← All Labs
🛡 AUTH INTERMEDIATE +90 XP · +40 no-hint bonus

Password Reset — Predictable Token

OldMail's password reset uses a token that's just the user's ID + the current timestamp, base64-encoded. Reset the admin's password by guessing the token.

https://bookshop.local/search