Hello guys hope this blog will give some knowledge , lets start.
Medium Blogs : https://medium.com/@test123cybertest
Recon:
Let s take my target as target.com , as usual collected a subdomains using subdomainfinder.c99.nl but i got only 20+ subdomains , soo i went through the manual recon using google dorks.
lets start , i used normal dorks like”site:.target.com” , but i got a repeated subdomains which i saw in subdomainfinder.c99.nl , soo lets filter this , ignore unwanted subdomains using this dork like “site:.target.com -www -ping -cdn -connect “ , finally found one subdomains like mail.target.cloud .
Enumeration:
This subdomain look like a admin and users mailing portal, i used wappalyzer for enumeration more and also showed some basics services like cloudflare , apache , php but in noticed the that mail service provide by third party “mailenable”

I tried normal admin credentials and default passwords , my bad nothing interest :( , ok its time to research . after that i went to mailenable.com support team questions and answers and i noticed one like “The AUTH.tab does not exist in my bin” . here a take a look a credientials using the auth.tab files (its both in localhost also but some developers saved in web servers to make api calls easier)

after know the “keyword”, i went to domain and add /AUTH.tab its showing 404 but /AUTH.txt is 403
Exploitation:
opened my kali and went to the 403 bypass tool , which is my fav “https://github.com/Dheerajmadhukar/4-ZERO-3”
after fuzzing i got one 200 which is it accepts POST request , then what !!!!! type
curl -i -X POST http://mail.target.com//AUTH.txtInside this i got a credentials , i dont wanna to expose here , and tried login attempt , yeah!!!! its succeed.

Reported:
Finally make a report on this to the organization and explianed good and also how to resolve this after conversation , they provide small bounty to me ($25) because reason of this is “third party”(shitty things)

Thanks for reading this tiny blog and Stay connect on instagram @cybersec_praveenarsh
