SPF Flag Missing | Mail Server misconfiguration
Submitted by Puneet Kumar maurya
Assigned to The GIMP web bugs mail alias
Link to original bug (#795725)
Description
Created attachment 371583 Vulnerable to spf
An SPF record is a type of Domain Name Service (DNS) record that identifies which mail servers are permitted to send email on behalf of your domain. The purpose of an SPF record is to prevent spammers from sending messages with forged From addresses at your domain. Steps To Reproduce:
- Checking Missing SPF:- There Are Various Ways of Checking Missing SPF Records on a website But the Most Common and Popular way is kitterman.com Steps to Check SPF Records on a website:- Go to http://www.kitterman.com/spf/validate.html Enter Target Website Ex: acorns.com (Do Not Add https/http or www) Hit Check SPF (IF ANY) If You seem any SPF Record than Domain is Not Vulnerable But if you see no SPF record here, it is vulnerable.
- Attack Scenario & PoC:- Once There is No SPF Records.An Attacker Can Spoof Email Via any Fake Mailer Like Emkei.cz.An Attacker Can Send Email From name "Support" or any contact handle of any gimp.org and Email: "support@target.com" With Social Engineering Attack He Can TakeOver User Account Let Victim Knows the Phishing Attack but When He See The Email from the Authorized Domain.He Got tricked Easily.
EXTRA INFO Impact : Attacker can use official mail of gimp.org for phishing attack. contact email of gimo which can be used for phishing attack. At it is from official mail, user will definitely trust it and will be tricked in phishing trap.