Password Reset MITM: Exposing the need for better security choices – Help Net Security
Attackers that have set up a malicious site can use users’ account registration process to successfully perform a password reset on popular websites.
Source: Password Reset MITM: Exposing the need for better security choices – Help Net Security