osTicket

attacking_common_applications

osticket is an open-source ticketing system. It is written in PHP and uses a MySQL database as the backend.

πŸ“š You can identify osTicket from the OSTSESSID cookie.

As a pentester, compromising a ticketing platform is often handy.

  • πŸ”‘ We may gain access to valid emails, either to access company-only platforms or perform social attacks

  • πŸ’΅ We may gain access to sensitive information

  • πŸ”« We may find usernames for other attacks

  • πŸ” We may be able to create users