email-spoofing

2 articles
sort: new top best
clear filter
0 6/10

A researcher discovered an SSRF vulnerability in Adfly's URL shortening service that allowed sending arbitrary emails via the SMTP protocol using Gopher protocol manipulation. By uploading a PHP file with a Gopher payload to a third-party server and shortening it through Adfly, the attacker could trigger email spoofing from the Adfly SMTP server.

Adfly Rafli Pasya Zerb0a Gopherus SMTP
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 6/10

Researcher discovered a wildcard subdomain takeover vulnerability on uber.design by identifying that the domain's wildcard DNS pointed to Heroku's unclaimed infrastructure, allowing registration of arbitrary subdomains (*.uber.design) and potential email spoofing via Google Workspace verification.

Uber HackerOne Heroku Google G-Suite Muhammad Khizer Javed uranium238
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details