• Resolve the host to ip then run directory bruteforce for info disclosure
  • Test on functions that allow you to add external resources
  • GET https://burpcollaboratorhere/ HTTP/1.1