A structured lesson workspace with readable content, hands-on examples, and a clean path to completion.
What if I told you that submitting a support ticket could give you a valid company email address? An address you can use to register on their GitLab, join their Slack workspace, or reset passwords on their VPN portal? That's osTicket.
Many osTicket installations assign a temporary internal email address to new tickets. Something like ticket-847292@support.inlanefreight.local. If the help desk correlates ticket numbers with emails, any message sent to that address appears in the ticket thread.
During an external assessment, I found leaked credentials via Dehashed: jclayton:JulieC8765! and kgrimes:Fish1ng_s3ason!. Neither worked on the osTicket login. But the login accepted email addresses. [email protected] with Fish1ng_s3ason! got me in as a support agent.
One closed ticket showed a support agent resetting a user's VPN password to the standard new-joiner password. Then sending that password directly in the ticket. The user never changed it. The standard password worked for three other employees on the VPN portal.
Support agents regularly share passwords in ticket threads, use standard reset passwords, and reference internal systems. If you gain access to a support queue, read every ticket. Export the address book. The data is gold.
Not every application needs to be directly exploitable to compromise an organization. Sometimes the support portal is the bridge between your OSINT and their internal systems. Would you check for ticket-to-email correlation on every help desk you find?
Finish the lesson once you have worked through the material. This awards ★ 20 XP.