Comment on page
Check if you can figure out when a username has already been registered inside the application.
Creating a user check the password policy (check if you can use weak passwords). In that case you may try to bruteforce credentials.
when registered try to change the email and check if this change is correctly validated or can change it to arbitrary emails.
- Check if you can use disposable emails
- Long password (>200) leads to DoS
- Check rate limits on account creation
- Use username@burp_collab.net and analyze the callback