Know the people who do insurance.

Request a Login

If you have not downloaded the username list, do so here. If you did, procede to the next hint.

BurpSuite is a handy tool to automating requests

  1. Download the username list to your downloads directory
  2. Launch BurpSuite
  3. Depending on your BurpSuite configuration, either launch the BurpSuite browser or use a Browser Extension
  4. Browswer -> Fill out the user profile registration form manually with any info you want
  5. BurpSuite -> Proxy Tab -> Turn on intercept to start capturing traffic
  6. Browser -> Click register button to submit the form
  7. BurpSuite -> You should see /api/users OPTIONS requet -> Forward
  8. You should see /api/users POST requet -> Right Click -> Send to Intruder
  9. Toggle off the proxy intercept off -> Go to Intruder tab
  10. Highlight the email address you used inside the double quotes -> Click the 'Add S' button next to POSITIONS to make it a position variable
  11. In the 'Payload Configuration' section click load -> Selet the EMAIL_LIST.txt file
  12. In the 'Payload Encoding' section, toggle off URL Encoding
  13. Click the Start Attack button -> Wait for the attack to finish -> Sort be response codes
  14. Select the one with the 418 response code -> Review the request and see the email was atorres@gmail.com