Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] **Bug Title : Missing SPF Records-neverlose.money leads to user manipulation.** #22

Open
Zer0Leet opened this issue Jan 30, 2022 · 2 comments
Assignees
Labels
bug Something isn't working

Comments

@Zer0Leet
Copy link

Describe the bug
Hi ,
There is any issue No valid SPF Records
Description :
There is an email spoofing vulnerability.Email spoofing is the forgery of an email header so that the message appears to have originated from someone or somewhere other than the actual source. Email spoofing is a tactic used in phishing and spam campaigns because people are more likely to open an email when they think it has been sent by a legitimate source. The goal of email spoofing is to get recipients to open, and possibly even respond to, a solicitation.

Impact: Any attacker can send Fake mails to the neverlose.money user's. The results can be more dangerous.

Remediation : Replace ~all with -all to prevent fake email.

Reference : https://www.digitalocean.com/community/tutorials/how-to-use-an-spf-record-to-prevent-spoofing-improve-e-mail-reliability

Screenshots
000
001
002

Bounty information

  1. Reporter's email address : yashahmed1337@gmail.com
  2. What crypto currency do you want to receive the bounty?: (BTC)
  3. Wallet address to receive the bounty: 1NSyPFzjPh7fKJp2KztxJ5drrNLYfwewsn
@Zer0Leet Zer0Leet added the bug Something isn't working label Jan 30, 2022
@Zer0Leet
Copy link
Author

Zer0Leet commented Feb 2, 2022

Any update on this?

1 similar comment
@Zer0Leet
Copy link
Author

Zer0Leet commented Feb 4, 2022

Any update on this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Development

No branches or pull requests

2 participants