0x22 - Phishing via Signup Forms
0x22 - Phishing via Signup Forms
Pentest Tips & Tricks
A01 - Broken Access Control
A01 - Broken Access Control
A02 - Cryptographic Failures
A02 - Cryptographic Failures
A03 - Injection Attacks
A03 - Injection Attacks
A04 – Insecure Design
A04 – Insecure Design
A05 – Security Misconfiguration
A05 – Security Misconfiguration
A06 – Vulnerable Components
A06 – Vulnerable Components
A07 – Identification and Authentication Failures
A07 – Identification and Authentication Failures
Recon & Attack Surface
Recon & Attack Surface
Tooling & Automation
Tooling & Automation
Creative, Strategic, and Mindset
Creative, Strategic, and Mindset
Bug Bounty $$$
Bug Bounty $$$
AI/ML/LLM/MCP
AI/ML/LLM/MCP
Latest Tips & Tricks
Latest Tips & Tricks
Did you know that in most cases you can abuse the registration forms to send phishing links to arbitrary addresses?
Most of the applications that I've tested are vulnerable to this.
Phishing emails exploiting this technique have a high rate of success because:
Emails end up in inbox
The sender is legitimate
Abuses the victim's curiosity
How to do it
Navigate to the registration form
Fill in the email address of the victim
Set the
firstnameandlastnameto a phishing URL that you control i.e:attacker.comhosting EvilNginx-
Victim receives a confirmation email such as "Welcome,
attacker.com.."