SPF Misconfiguration

Disclosed: 2017-11-06 09:03:07 By mr_r3boot To infogram
Low
Vulnerability Details
I am just looking at your SPF records then found following. SPF Records missing safe check which can allow me to send mail on behalf of infogram. #PoC: The TXT records found for your domain are: ``` "v=spf1 include:_spf.google.com include:spf.mandrillapp.com include:mailgun.org ~all" ``` Simply anyone can use ```https://emkei.cz/``` service to trigger mail to anyone on behalf of infogram. #Fix: ```v=spf1 include:_spf.google.com include:spf.mandrillapp.com include:mailgun.org -all``` >#*If team don't wanna hear about spf related checks please let me know. i'll close this report myself.* Regards, Mr.R3boot.
Actions
View on HackerOne
Report Stats
  • Report ID: 280408
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report