-
Notifications
You must be signed in to change notification settings - Fork 169
/
Copy path115232.txt
23 lines (16 loc) · 999 Bytes
/
115232.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
ReportLink:https://hackerone.com/reports/115232
WeaknessName:Violation of Secure Design Principles
Reporter:https://hackerone.com/null00null00
ReportedTo:Paragon Initiative Enterprises(paragonie)
BountyAmount:
Severity:
State:Closed
DateOfDisclosure:17.06.2016 1:57:15
Summary:
There are few email spoofing tool is available free.one them is
http://emkei.cz/
when I tried to send a email from security@paragonie.com to my email ,it was successful but when i tried to send the another from shani@facebook.com , i did not receive any email.Hence, there might be some configuration missing in your mail servers (i am not much aware of technical details associated with this issue but would love to know how this is happening),A rice can explain this to me much better.
This can be dangerous ,as attacker can send some fake Detail to some hacker,then hacker will claim back for the money (a sample mail attached),can lead to reputation loss :)
please have a look
Thanks
POC