0x04 - Reading Intercom Widget Messages
0x04 - Reading Intercom Widget Messages
Pentest Tips & Tricks
A01 - Broken Access Control
A01 - Broken Access Control
A02 - Cryptographic Failures
A02 - Cryptographic Failures
A03 - Injection Attacks
A03 - Injection Attacks
A04 – Insecure Design
A04 – Insecure Design
A05 – Security Misconfiguration
A05 – Security Misconfiguration
A06 – Vulnerable Components
A06 – Vulnerable Components
A07 – Identification and Authentication Failures
A07 – Identification and Authentication Failures
Recon & Attack Surface
Recon & Attack Surface
Tooling & Automation
Tooling & Automation
Creative, Strategic, and Mindset
Creative, Strategic, and Mindset
Bug Bounty $$$
Bug Bounty $$$
AI/ML/LLM/MCP
AI/ML/LLM/MCP
Latest Tips & Tricks
Latest Tips & Tricks
Did you know you can read the chat messages of other users in the Intercom Widgets with just 2 JavaScript commands?
Intercom is a very popular chat widget used by applications to provide customer support.
However, due to a common misconfiguration (identity verification not enabled) it's possible to impersonate any email address and read previous conversations.
Here is just an example of how it can be used to take over accounts https://dday.us/2021/11/03/h1vendorATO.html
How to do it
Open browser developer tools
Run
𝐈𝐧𝐭𝐞𝐫𝐜𝐨𝐦('𝐬𝐡𝐨𝐰');to check if the widget is usedIf the widget shows up, run
𝐈𝐧𝐭𝐞𝐫𝐜𝐨𝐦('𝐛𝐨𝐨𝐭', { 𝐞𝐦𝐚𝐢𝐥: '<𝐯𝐢𝐜𝐭𝐢𝐦_𝐞𝐦𝐚𝐢𝐥>' });Open the chat and check for old conversations
If there are no old conversation, the target email has not been used in previous conversations.
If you get Intercom Messenger error: Missing user_hash. A valid user_hash is required -> Not vulnerable