Email spoofing-fake mail from your mail domain server

Disclosed: 2016-08-27 04:57:11 By sumit7 To legalrobot
Unknown
Vulnerability Details
Hiii THERE **Vulnerability Title** There are few email spoofing tool is available free.one them is http://emkei.cz/ **Description** when I tried to send a email from [email protected] to my email ,it was successful but when i tried to send the another from [email protected] , i did not receive any email. there might be some configuration missing in your mail servers. **Attack Scenario** Any attacker sends to user of legal robot and that directly comes in Inbox of user, generally user believes that that is authenticate because it directly comes in Inbox and comes from mail domain server of legalrobot. **Important** Fake mail should be not possible if you refer hackerone, twitter, facebook, anagami etc either Any fake mail should be come in folder of Spam POC: Fake mail in inbox from legalrobot mail domain Happy to help to secure cyber word **Thanks** **SMIT GAJRA** Information security researcher
Actions
View on HackerOne
Report Stats
  • Report ID: 163501
  • State: Closed
  • Substate: informative
  • Upvotes: 5
Share this report