Tuesday, October 6, 2026

Inside splitting-the-email-atom: probing email parser discrepancies to test access controls

Inside splitting-the-email-atom: probing email parser discrepancies to test access controls

splitting-the-email-atom packages Gareth Heyes' Black Hat and DEF CON research on email address parser discrepancies, with fuzzers, Hackvertor tags and demo code for authorized testing.

ToolPortSwigger/splitting-the-email-atom — research materials and tooling for exploring email address parser discrepancies that can bypass access controls
CategoryWeb security research toolkit (fuzzing, parsing, Burp Suite extensions)
Primary UseReproducing and studying email parser discrepancy bugs in authorized targets, using the CSS exfiltrator, Hackvertor tags, PHP Punycode fuzzer and Turbo Intruder scripts
Safe UseEducational and documentary analysis for authorized professionals: use against lab environments, the Web Security Academy CTF, and systems you own or have written permission to test
Telemetry NoteThe SMTP fuzzing and Turbo Intruder components generate high volumes of malformed email traffic against any target they are pointed at, which will appear in mail server and WAF logs; defenders should watch for anomalous encoded address variants

PortSwigger/splitting-the-email-atom is the companion repository to Gareth Heyes' conference talk "Splitting The Email Atom: Exploiting Parsers To Bypass Access Controls", presented at Black Hat and DEF CON and later at NDC Manchester 2025. Rather than a single installable utility, the repo collects the full research apparatus behind the work: the code used in the live Joomla demonstration, a tools directory with several purpose-built utilities, slides, and pointers to a Web Security Academy lab. The primary research writeup lives at portswigger.net/research/splitting-the-email-atom, and the repo is best understood as the executable annex to that long-form analysis.

The core problem the research addresses is parser differential handling of email addresses. Email address syntax is deceptively complex, spanning RFC grammar, internationalization via Punycode, quoted local parts, comments and encoded-word constructs. When two components in the same application — say an inbound mail gateway and the web application that later parses the same address for an access-control decision — disagree on how to split or normalize an address, that disagreement becomes a logic-flaw primitive. The repository exists to let authorized researchers systematically discover and demonstrate those disagreements instead of hunting them by hand.

Structurally, the repo is organized around a few directories that the README names explicitly. The Joomla directory contains the code to replicate the live demo shown on stage, reconstructing the vulnerable scenario in a controlled environment. The tools directory is where most of the durable value sits, and the README enumerates its contents: a CSS exfiltrator, Hackvertor tags, a PHP Punycode fuzzer, a converter, SMTP fuzzing scripts and Turbo Intruder scripts. That inventory tells you the research workflow spanned generation, transformation, delivery and detection — the full lifecycle of a parser-discrepancy investigation.

The PHP Punycode fuzzer and the converter point at the internationalization angle, which is a recurring theme in this class of bug. Punycode encodes internationalized domain names into an ASCII-compatible representation, but different libraries normalize and decode those representations inconsistently. A fuzzer targeting PHP's handling specifically suggests the research validated discrepancies against the parser stack that powers a large fraction of deployed web applications, and the converter presumably translates between encoded forms so researchers can move an address between representations when testing how each layer interprets it.

The SMTP fuzzing scripts operate at the protocol layer, which matters because the discrepancy being probed often begins before the web application ever sees the address. Mail servers, forwarding logic and web frameworks each apply their own parsing rules to the same RFC 5322-shaped input, and malformed or edge-case addresses — unusual quoting, nested comments, mixed encodings — can be interpreted differently at each hop. Fuzzing over SMTP lets a researcher enumerate which malformed forms survive delivery and what shape they arrive in, which is precisely the raw material for a downstream access-control bypass.

On the Burp Suite side, the repository ties into two of PortSwigger's well-established extensions: Turbo Intruder for high-rate request manipulation and Hackvertor for transformation-based payload generation. The custom Hackvertor tags mentioned in the README are designed to help produce email splitting attacks — in practice, encoding and re-encoding address fragments so that a proxy, a backend parser and an application-level check each see a different effective address. Turbo Intruder scripts then let an authorized tester replay candidate discrepancies against a lab target at scale to confirm which interpretations actually diverge.

The CSS exfiltrator is the most unusual component in the set. In the talk's narrative, exfiltration via Cascading Stylesheets — for example leaking attribute content through selectively-styled selectors that trigger outbound requests — demonstrates how a parser discrepancy can escalate from a theoretical mismatch to observable data exposure. As a research artifact it doubles as a defensive reference: blue teams reviewing the code can understand exactly which CSS constructs to scrutinize when user-controlled content influences stylesheets, and why sanitizing email-derived values matters beyond the obvious injection vectors.

For anyone wanting structured practice, the README links a dedicated CTF on the Web Security Academy under the logic-flaws module, specifically the email-address-parser-discrepancies example. That lab is the sanctioned sandbox for exercising these techniques, and it is the right first stop before touching the Joomla demo code or pointing any of the fuzzers elsewhere. The slides from Black Hat US 24 and the NDC Manchester 2025 deck are also linked directly, giving the conceptual framework that the code alone does not convey — the taxonomy of discrepancies, the affected parser families, and the reasoning about where trust boundaries break down.

Operationally, this is a research and education repository, not a maintained product. It is written primarily in HTML per the repository metadata, sits at a modest ~99 stars, carries no explicit license at the time of writing, and has no topics tagged. That profile fits a talk-artifact repo: value comes from studying and locally reproducing the techniques, not from expecting release cadence or support. Anyone cloning it should treat the components as reference implementations and review them before running anything, particularly the fuzzing scripts, which by nature send large volumes of malformed traffic.

From a defensive standpoint, the repository is arguably more useful to builders and defenders than to attackers with malicious intent, because the interesting findings have already been disclosed publicly through the talk, the research paper and the Academy lab. Engineering teams that route email addresses through multiple parsers — signup flows, password reset logic, allowlist checks, mail gateways — can use the documented discrepancy classes as a test matrix: confirm that every component in the chain agrees on canonicalization before any authorization decision is made. The single most actionable mitigation is to parse once, canonicalize, and pass the canonical form forward rather than re-parsing raw input at each layer.

In sum, PortSwigger/splitting-the-email-atom is a well-documented snapshot of serious parser research from a vendor with a strong disclosure track record. For authorized professionals it offers a rare look at the complete toolchain behind a conference talk — fuzzers, transformation tags, protocol scripts and a live demo target — and a safe, structured path to practice via the Web Security Academy. Use it in labs and sanctioned engagements, respect the absence of a license, and treat the SMTP and Turbo Intruder components as the noisy, log-visible operations they are.

Official project repository for PortSwigger/splitting-the-email-atom.
Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.

Share articleFacebookXLinkedIn

Continue exploring

Browse all articles →

0 comentários:

Post a Comment

Note: Only a member of this blog may post a comment.