6 ms·
One given example is that – in the case of the Return-Path header being maliciously set – the attacker could perform a DoS attack on the victim's mailbox so tha
by lushc 9y ago
One given example is that – in the case of the Return-Path header being maliciously set – the attacker could perform a DoS attack on the victim's mailbox so that the password reset email would be sent as part of a non-delivery receipt.
- 1_player 9y agoAlso, if the victim has an auto-responder enabled, the attacker will receive an out of office reply, with the password reset link quoted in the email.
- corobo 9y agoI've never seen an autoreply that's included the original message
- matt_morgan 9y agoIt was always rare, but it used to be more common than it is now.
- atomt 9y agoAnother way to trigger a bounce would be to have the evil domain purposefully having strict SPF and DMARC policy set.
- gondo 9y agothis depends on recipient's (WP admin) server properly validating SPF and DMARC