0x53 - Using Collaborator as Email Inbox
0x53 - Using Collaborator as Email Inbox
Pentest Tips & Tricks
A01 - Broken Access Control
A01 - Broken Access Control
A02 - Cryptographic Failures
A02 - Cryptographic Failures
A03 - Injection Attacks
A03 - Injection Attacks
A04 – Insecure Design
A04 – Insecure Design
A05 – Security Misconfiguration
A05 – Security Misconfiguration
A06 – Vulnerable Components
A06 – Vulnerable Components
A07 – Identification and Authentication Failures
A07 – Identification and Authentication Failures
Recon & Attack Surface
Recon & Attack Surface
Tooling & Automation
Tooling & Automation
Creative, Strategic, and Mindset
Creative, Strategic, and Mindset
Bug Bounty $$$
Bug Bounty $$$
AI/ML/LLM/MCP
AI/ML/LLM/MCP
Latest Tips & Tricks
Latest Tips & Tricks
Did you know that Burp Collaborator listens to SMTP messages, on top of HTTP and DNS?
This means that you can use the collaborator as a throw away email address and register as many accounts on your target platform as you want.
Most applications will send you a verification code which you can also read from the SMTP body and confirm that the email is valid.
Best part is that you can have as many unique email addresses as you want without "registering" a new email inbox.
Worst part is that you'll lose access to the inbox. But that's what throw away emails are for, right?
How to do it
Navigate to the registration page of the app (in my case Linkedin)
Copy the collaborator URL from Burp and use it as domain for your email (i.e:
test@onfqio8a5qv1kuzw0iwchs3q7hd81zpo.oastify.com)Check the collaborator requests for SMTP messages
Use the confirmation code in the message to confirm the legitimacy of your email