Auth Related (more in logic, priv, and transport sections)
Session Related:
Login testing:
Host: evil.com – does reset link use evil.com?myemail%00@email.com – null byte truncation to real accountreturnUrl, goto, return_url, backSession bugs:
Account takeover chains: