Found a site with a potentially severe vulnerability, how owuld you all go about executing such an attack?
2024-4-15 08:7:51 Author: 0x00sec.org(查看原文) 阅读量:4 收藏

1

For privacy obviously I wont share the site name, but the site is vulnerable explained in the following cve:

Seems like the attack is basically executed by a hacker listening to a victims email, and then when they recieve that victims packet they can manipulate it to execute remote commands like: RCPT TO:[email protected]

or maybe other more malicious requests? am i understanding that right?

which would mean in order to get the attack to work i would need to have a user from that site in a mitm attack of sorts and wait for them to request a email or send an email?


文章来源: https://0x00sec.org/t/found-a-site-with-a-potentially-severe-vulnerability-how-owuld-you-all-go-about-executing-such-an-attack/40064
如有侵权请联系:admin#unsafe.sh