gopher-protocol

1 article
sort: new top best
clear filter
0 6/10

A researcher discovered an SSRF vulnerability in Adfly's URL shortening service that allowed sending arbitrary emails via the SMTP protocol using Gopher protocol manipulation. By uploading a PHP file with a Gopher payload to a third-party server and shortening it through Adfly, the attacker could trigger email spoofing from the Adfly SMTP server.

Adfly Rafli Pasya Zerb0a Gopherus SMTP
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details