MrSentex / SpotCheck

Account checker for Spotify music service.
24 stars 18 forks source link

Using SpotCheck on an account triggers an email alert #5

Open rafaelsgirao opened 5 years ago

rafaelsgirao commented 5 years ago

The title pretty much sums it up - I used SpotCheckon a dummy account I have and got an email alert saying my password was reset. I'm guessing the CSRF evasion method it uses is no longer viable

MrSentex commented 5 years ago

Hi!.

The CSRF bypass is good. If the bypass fail, all the requests will be broken. Maybe Spotify increase their security.

I don't have time to support the program so I can't fix nothing at the moment.