What to do with an email? 06-05-2013, 12:14 PM
#1
Hello everybody,
first of all: this is a 'tutorial' in the wide definition of the word. I'll be giving you tips and tricks on what you can do with an email-account. Most of them will be obvious, but there may be some cool tricks that you didn't know of. Now, lets start, shall we?
Alright, so lets say you've got into a site (SQLi, Bruteforce,...) and you've stumbled upon a list full of emails and passwords. Ofcourse it's for the site and not for their real email, but you'll be amazed how many people use the same password for their email too. So, you've got into a couple of sweet email accounts and want to play with it. What now?
Although this is quite obvious, a lot of people tend to forget this. When you've got somebody's email put it in the searchbar in facebook. If there's an account linked to it, it'll show up! Great, now we know our 'victim' got facebook. Lets go to the homepage of facebook and click on 'Forgot your password?' (Link: https://www.facebook.com/login/identify?ctx=recover). Fill in the email of the victim and click SEARCH.
![[Image: fb1d.png]](http://img708.imageshack.us/img708/7772/fb1d.png)
Now hope that facebook will ask you to send a facebook reset to the email. Click on 'continue'.
Now go to the victims email. Now there will be a code send to you.
![[Image: fb3x.png]](http://imageshack.us/a/img560/404/fb3x.png)
Fill in the code in the desired area.
![[Image: fb2qx.png]](http://imageshack.us/a/img835/9485/fb2qx.png)
Now it will ask you for a new password. Just type any password in you like. Be sure to check the checkbox that says 'Log me off on any connected devices'.
![[Image: fb4kt.png]](http://imageshack.us/a/img15/5217/fb4kt.png)
Now click continue. And congratulations, you're in!
![[Image: fb5v.png]](http://imageshack.us/a/img593/299/fb5v.png)
This is just like facebook, but then with other accounts. Search your victims email for any site that requires registration. For this example I'll take 'kapaza'. It's an online shop, like eBay.
![[Image: 68178681.png]](http://imageshack.us/a/img534/3264/68178681.png)
Now I know my victim is registered with that email on kapaza. So let's go to that site and click on 'Forgot password?' (or something similar to that). Most of the time it'll ask for your email. Fill that in.
![[Image: 33662742.png]](http://imageshack.us/a/img32/2160/33662742.png)
Alright, click on 'send' and now go back to the victims inbox. Normally there should be a password reset link.
![[Image: 37045372.png]](http://imageshack.us/a/img24/3049/37045372.png)
Click on it and put your new password.
![[Image: 26581613.png]](http://imageshack.us/a/img838/7483/26581613.png)
And done! You've changed the victims password. You can do this with most of the sites.
![[Image: 25517732.png]](http://imageshack.us/a/img822/8031/25517732.png)
This one is really fun if you have the login email of someones ISP. When you have an email list, search for things like @ispname.com.
I'll take @telenet.be for example. I've got an email list and got about 6 ISP accounts from it. Now I can access their ISP control panel.
![[Image: 49247793.png]](http://imageshack.us/a/img690/3185/49247793.png)
Go to the ISP login page and login with the victims ISP details. Then look in the navigation menu for something fun. In my menu there's a button called 'Internet'. Lets click on that.
![[Image: 12477773.png]](http://imageshack.us/a/img822/4631/12477773.png)
This looks pretty nice. I can make a new email with @telenet.be, look at how much bandwith they got and I can access the telenet hotspots! First, let's make my new, awesome @telenet email!
![[Image: 66475522.png]](http://imageshack.us/a/img844/2069/66475522.png)
Here I'm making a new user so I can make a new mailbox with it! I've put up an online cellphone number, because sometimes you need verification (not on this one, though). You can check online cellphone numbers that you can use on http://receive-sms-online.com/
Alright, and now just make your mail! I've made a mail named 'anongen@telenet.be'. How cool is that?
![[Image: 76889841.png]](http://imageshack.us/a/img818/4606/76889841.png)
Now you've got a cool email, lets look at those hotspots telenet provide their customers!
Lets go to 'Hotspotaccess' in the navigation menu.
![[Image: 77729917.png]](http://imageshack.us/a/img5/9508/77729917.png)
And here it says our hotspot is active and they give us our username! Now we can login into the hotspots that telenet provide us!
I'm sure there are many more things that you can do with an email, but I find those the best. If you've got anything more, I'll be happy to add it!
I hope you enjoyed this tutorial. This took me some time to make, it only takes 10 seconds of your live to reply.
Cheers!
first of all: this is a 'tutorial' in the wide definition of the word. I'll be giving you tips and tricks on what you can do with an email-account. Most of them will be obvious, but there may be some cool tricks that you didn't know of. Now, lets start, shall we?
Alright, so lets say you've got into a site (SQLi, Bruteforce,...) and you've stumbled upon a list full of emails and passwords. Ofcourse it's for the site and not for their real email, but you'll be amazed how many people use the same password for their email too. So, you've got into a couple of sweet email accounts and want to play with it. What now?
#1: RESET FACEBOOK PASSWORD
Although this is quite obvious, a lot of people tend to forget this. When you've got somebody's email put it in the searchbar in facebook. If there's an account linked to it, it'll show up! Great, now we know our 'victim' got facebook. Lets go to the homepage of facebook and click on 'Forgot your password?' (Link: https://www.facebook.com/login/identify?ctx=recover). Fill in the email of the victim and click SEARCH.
![[Image: fb1d.png]](http://img708.imageshack.us/img708/7772/fb1d.png)
Now hope that facebook will ask you to send a facebook reset to the email. Click on 'continue'.
Now go to the victims email. Now there will be a code send to you.
![[Image: fb3x.png]](http://imageshack.us/a/img560/404/fb3x.png)
Fill in the code in the desired area.
![[Image: fb2qx.png]](http://imageshack.us/a/img835/9485/fb2qx.png)
Now it will ask you for a new password. Just type any password in you like. Be sure to check the checkbox that says 'Log me off on any connected devices'.
![[Image: fb4kt.png]](http://imageshack.us/a/img15/5217/fb4kt.png)
Now click continue. And congratulations, you're in!
![[Image: fb5v.png]](http://imageshack.us/a/img593/299/fb5v.png)
#2: GAIN CONTROL OVER ALL REGISTERED ACCOUNTS
This is just like facebook, but then with other accounts. Search your victims email for any site that requires registration. For this example I'll take 'kapaza'. It's an online shop, like eBay.
![[Image: 68178681.png]](http://imageshack.us/a/img534/3264/68178681.png)
Now I know my victim is registered with that email on kapaza. So let's go to that site and click on 'Forgot password?' (or something similar to that). Most of the time it'll ask for your email. Fill that in.
![[Image: 33662742.png]](http://imageshack.us/a/img32/2160/33662742.png)
Alright, click on 'send' and now go back to the victims inbox. Normally there should be a password reset link.
![[Image: 37045372.png]](http://imageshack.us/a/img24/3049/37045372.png)
Click on it and put your new password.
![[Image: 26581613.png]](http://imageshack.us/a/img838/7483/26581613.png)
And done! You've changed the victims password. You can do this with most of the sites.
![[Image: 25517732.png]](http://imageshack.us/a/img822/8031/25517732.png)
#3: ACCESSING THEIR ISP DETAILS
This one is really fun if you have the login email of someones ISP. When you have an email list, search for things like @ispname.com.
I'll take @telenet.be for example. I've got an email list and got about 6 ISP accounts from it. Now I can access their ISP control panel.
![[Image: 49247793.png]](http://imageshack.us/a/img690/3185/49247793.png)
Go to the ISP login page and login with the victims ISP details. Then look in the navigation menu for something fun. In my menu there's a button called 'Internet'. Lets click on that.
![[Image: 12477773.png]](http://imageshack.us/a/img822/4631/12477773.png)
This looks pretty nice. I can make a new email with @telenet.be, look at how much bandwith they got and I can access the telenet hotspots! First, let's make my new, awesome @telenet email!
![[Image: 66475522.png]](http://imageshack.us/a/img844/2069/66475522.png)
Here I'm making a new user so I can make a new mailbox with it! I've put up an online cellphone number, because sometimes you need verification (not on this one, though). You can check online cellphone numbers that you can use on http://receive-sms-online.com/
Alright, and now just make your mail! I've made a mail named 'anongen@telenet.be'. How cool is that?
![[Image: 76889841.png]](http://imageshack.us/a/img818/4606/76889841.png)
Now you've got a cool email, lets look at those hotspots telenet provide their customers!
Lets go to 'Hotspotaccess' in the navigation menu.
![[Image: 77729917.png]](http://imageshack.us/a/img5/9508/77729917.png)
And here it says our hotspot is active and they give us our username! Now we can login into the hotspots that telenet provide us!
#4: THE END?
I'm sure there are many more things that you can do with an email, but I find those the best. If you've got anything more, I'll be happy to add it!
I hope you enjoyed this tutorial. This took me some time to make, it only takes 10 seconds of your live to reply.
Cheers!