DMARC and DNS Records not found on mcuboot.com

Disclosed: 2021-05-10 17:26:32 By dk82hg To mcuboot
Unknown
Vulnerability Details
Found no DMARC and DNS record on mcuboot.com . I am also able to send an email to me on your behalf . The mail sent didnot even landed in spam folder which could make the users believe on the attacker as a legitimate person or authority. Any attacker could do so by using any fake mailer .For exmple : Emkei's Fake mailer - emkei.cz Screenshots have been attached for the same. ## Impact An attacker can spoof any mcuboot.com email address . This could allow them to appear to be a high-profile individual or company.
Actions
View on HackerOne
Report Stats
  • Report ID: 1186701
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report