Email spoofing-fake mail from your mail domain server
L
Legal Robot
Submitted None
Actions:
Reported by
sumit7
Vulnerability Details
Technical details and impact analysis
Hiii THERE
**Vulnerability Title**
There are few email spoofing tool is available free.one them is
http://emkei.cz/
**Description**
when I tried to send a email from [email protected] to my email ,it was successful but when i tried to send the another from [email protected] , i did not receive any email. there might be some configuration missing in your mail servers.
**Attack Scenario**
Any attacker sends to user of legal robot and that directly comes in Inbox of user, generally user believes that that is authenticate because it directly comes in Inbox and comes from mail domain server of legalrobot.
**Important**
Fake mail should be not possible if you refer hackerone, twitter, facebook, anagami etc either Any fake mail should be come in folder of Spam
POC: Fake mail in inbox from legalrobot mail domain
Happy to help to secure cyber word
**Thanks**
**SMIT GAJRA**
Information security researcher
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Improper Authentication - Generic