[INS’hAck 2019]Atchap

[INS’hAck 2019]Atchap

分析

利用邮件服务器漏洞

Tchap: The super (not) secure app of the French government

payload

buu注册一个邮箱

发送自己的邮箱,提示

1
You're not whitelisted or not part of the company..

发送下面contact us的邮箱Samira.Bien@almosttchap.fr

1
You're not using your official address..

发送

1
yourmail@mail.com@Samira.Bien@almosttchap.fr

在邮箱中查看邮件中得到flag