Skip Menu |

This queue is for tickets about the Finance-Bank-HDFC CPAN distribution.

Report information
The Basics
Id: 132666
Status: new
Priority: 0/
Queue: Finance-Bank-HDFC

People
Owner: Nobody in particular
Requestors: grvkmr157 [...] gmail.com
Cc:
AdminCc:

Bug Information
Severity: (no value)
Broken in: (no value)
Fixed in: (no value)



Subject: Improper Authentication - Generic
Date: Thu, 21 May 2020 13:51:50 +0530
To: bug-Finance-Bank-HDFC [...] rt.cpan.org
From: gaurav Mishra <grvkmr157 [...] gmail.com>
Hiii, There is any issue No valid SPF Records Desciprition : There is a email spoofing vulnerability.Email spoofing is the forgery of an email header so that the message appears to have originated from someone or somewhere other than the actual source. Email spoofing is a tactic used in phishing and spam campaigns because people are more likely to open an email when they think it has been sent by a legitimate source. The goal of email spoofing is to get recipients to open, and possibly even respond to, a solicitation. I found : v=spf1 include:nlsmtp.com ~all Remediation : Replace ~all with -all to prevent fake email. Refrences: https://mxtoolbox.com/SuperTool.aspx Also evaluating with SPF record passed validation test with pySPF (Python SPF library) Use the back button on your browser to return to the SPF checking tool without clearing the form. https://www.digitalocean.com/community/tutorials/how-to-use-an-spf-record-to-prevent-spoofing-improve-e-mail-reliability Impact : An attacker would send a Fake email. The results can be more dangerous. Thanks & Regards Gaurav Kumar
Download error.PNG
image/png 163.8k

Message body is not shown because sender requested not to inline it.

Download error2.PNG
image/png 50.3k

Message body is not shown because sender requested not to inline it.