Email spoofing possible via Legal Robot domain

Disclosed: 2017-01-21 06:38:29 By swapnil755 To legalrobot
Unknown
Vulnerability Details
Dear Team, There are few email spoofing tools available on for free and one of them is http://emkei.cz/ When i tried to send an email from [email protected] to my mail, it was successful and straight away delivered into my inbox but when i tried to send it from another mail id [email protected],[email protected], i did not receive any mail. Hence there might be some configuration missing in your mail servers (i am not much aware of technical details associated with this issue but would love to know how this is happening) This can be dangerous, as attacker can send some fake mails with any fake promotional mails and ask for account details or it can be anything.This thing can also lead to reputation loss. PFA screenshots of mail delivered to my account.Please feel free if you need any further help. Thanks & Regards, Swapnil Kothawade.
Actions
View on HackerOne
Report Stats
  • Report ID: 163475
  • State: Closed
  • Substate: informative
  • Upvotes: 1
Share this report