•  
      bugs #6434 Missing SPF Records
    #6434
    Priyesh Mali (priyash)
    2019-11-20 12:20
    2019-11-20 12:20
    Details
    Missing SPF Records
    An SPF record is a type of Domain Name Service (DNS) record that identifies which mail servers are permitted to send email on behalf of your domain. The purpose of an SPF record is to prevent spammers from sending messages with forged From addresses at your domain.
    Checking Missing SPF:-
    There Are Various Ways of Checking Missing SPF Records on a website But the Most Common and Popular way is kitterman.com

    Steps to Check SPF Records on a website:-
    1) Go to http://www.kitterman.com/spf/validate.html

    Enter Target Website Ex: target.com (Do Not Add https/http or www)
    Hit Check SPF (IF ANY)

    If You seem any SPF Record than Domain is Not Vulnerable But if you see Nothing Here then "HURRAY! You Found a Bug"

    2) Attack Scenario & PoC:-
    Once There is No SPF Records.An Attacker Can Spoof Email Via any Fake Mailer Like Emkei.cz.An Attacker Can Send Email From name "Support" and Email: "support@target.com".

    3) Finally You Get Mail
    -----------------------------------------------------------------------------------------------------------------------------------------
    Just Go Through ScreenShots.
    9 - Critical
    Empty
    Stage
    Empty
    Will not fix
    Empty
    Attachments
    There is zip File of 3 PNG Screenshots attachment.
    References
    References list is empty