Open-source ticketing systems written in PHP with a MySQL backend.
Enumeration
osTicket instances will have a cookied named OSTSESSID when visiting the page. Visiting the webpage will also show powered by and an osTicket logo. The footer may also contain Support Ticket System.
We can break apart attacking such a web application as such:
- User Input: the core function of ticketing platforms is to inform the employees about a problem. Since this application is open source we can see that the admin panel is available to all users with the privileges. We can very easily social engineer the team managing the tickets
- Processing: Staff will try to reproduce the signficant errors found at the core of the problem. Processing is done internally in an isolated environment .
- Solution: Other technical departments will likely be involved in the email correspondence. This gives us new emails to use against the osTicket admin panel.
Attacking
Aside from being vulnerable to certain CVEs. Support portals can sometimes be used to obtain email address for a company domain. We may be able to submit a new ticket and obtain a valid company email address depending on the support platform logic.
Looking at tickets often reveals a lot of sensitive information that can be used for other parts of our assessment.