Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore advanced email parsing vulnerabilities and learn to exploit RFC-compliant email addresses that can bypass security controls and access restrictions. Discover how ancient email RFCs create parsing inconsistencies that attackers can leverage to craft malicious email addresses appearing legitimate while bypassing virtually all defensive measures. Master techniques for spoofing email domains, accessing internal systems protected by Zero Trust architectures, and circumventing employee-only registration barriers through parser discrepancies. Examine real-world exploitation scenarios across multiple applications and libraries, including methods for transforming harmless-looking input into malicious payloads that cause email misrouting and enable blind CSS injection attacks. Gain practical experience with a comprehensive methodology and toolkit for identifying vulnerable targets, plus hands-on practice through a dedicated capture-the-flag exercise designed to develop your email parsing exploitation skills.
Syllabus
Splitting the Email Atom: Exploiting Parsers to Bypass Access Controls - Gareth Heyes
Taught by
NDC Conferences