Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Splitting the email atom: exploiting parsers to bypass access controls (portswigger.net)
2 points by hackvertor on Sept 5, 2024 | hide | past | favorite | 1 comment


Some websites parse email addresses to extract the domain and infer which organisation the owner belongs to. This pattern makes email-address parser discrepancies critical. Predicting which domain an email will be routed to should be simple, but is actually ludicrously difficult - even for 'valid', RFC-compliant addresses.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: