3 ms·
I'm missing something - how can this be exploited? AFAICT it's only if a user replies to the email (and thereby includes the reset token)?
by jonathonf 9y ago
I'm missing something - how can this be exploited? AFAICT it's only if a user replies to the email (and thereby includes the reset token)?
- lushc 9y agoOne given example is that – in the case of the Return-Path header being maliciously set – the attacker could perform a DoS attack on the victim's mailbox so that the password reset email would be sent as part of a non-delivery receipt.
- 1_player 9y agoAlso, if the victim has an auto-responder enabled, the attacker will receive an out of office reply, with the password reset link quoted in the email.
- corobo 9y agoI've never seen an autoreply that's included the original message
- matt_morgan 9y agoIt was always rare, but it used to be more common than it is now.
- atomt 9y agoAnother way to trigger a bounce would be to have the evil domain purposefully having strict SPF and DMARC policy set.
- gondo 9y agothis depends on recipient's (WP admin) server properly validating SPF and DMARC
- zimbatm 9y agoIt has to be combined with another attack. If the victim's mail server bounces the email it will be sent back to the attacker's mail server. One possible approach to do that is to fill the target email so they reach their quota.