smtp

1 article
sort: new top best
clear filter
0 6/10

Researcher exploited an SSRF vulnerability on Adfly to gain access to the internal SMTP server via the Gopher protocol, enabling unauthorized email sending from the Adfly domain. The attack involved uploading a PHP redirect file to a third-party server that, when visited through Adfly's URL shortening feature, would execute a Gopher payload to interact with the local SMTP service.

Adfly Rafli Pasya Zerb0a Gopherus FastCGI
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 6 hours ago · details