Email Spoofing

Attack Diagram

Email Spoofing

# Tool
git clone https://github.com/BishopFox/spoofcheck
cd spoofcheck
python spoofcheck.py etisalat.com

# Manual
dig +short txt etisalat.com
dig +short txt _dmarc.etisalat.com

SMTP Open Relay

# Nmap
nmap -sV --script smtp-open-relay -v $target

# Telnet
telnet $IP_Address $SMTP_Port
> EHLO etisalat.com
> Mail From: <support@etisalat.com>
> RCPT To: <hassansaad0x@gmail.com>
> Data
> From: Support <support@etisalat.com>
> To: Hassan Saad <hassansaad0x@gmail.com>
> Subject: Updates
>
> Hello Hassan,
>
> This is an email sent by using the telnet command.
>
> Your friend.
> .
> Quit

Last updated