Loading HuntDB...

Email spoofing possible via Legal Robot domain

L
Legal Robot
Submitted None
Reported by swapnil755

Vulnerability Details

Technical details and impact analysis

Violation of Secure Design Principles
Dear Team, There are few email spoofing tools available on for free and one of them is http://emkei.cz/ When i tried to send an email from [email protected] to my mail, it was successful and straight away delivered into my inbox but when i tried to send it from another mail id [email protected],[email protected], i did not receive any mail. Hence there might be some configuration missing in your mail servers (i am not much aware of technical details associated with this issue but would love to know how this is happening) This can be dangerous, as attacker can send some fake mails with any fake promotional mails and ask for account details or it can be anything.This thing can also lead to reputation loss. PFA screenshots of mail delivered to my account.Please feel free if you need any further help. Thanks & Regards, Swapnil Kothawade.

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Violation of Secure Design Principles