Mohammad Mohsin
Apr 28, 2022

--

Hi @Bertrand, After account takeover I was able to send malicious emails to all the employees of the organization as SMTP was configured with the application. After some more research I was able to exploit SMTP Relay through which as an admin I could send phishing emails to thousands of employees of the same organization acting as a legitimate admin user.

--

--

Mohammad Mohsin
Mohammad Mohsin

Written by Mohammad Mohsin

Director - OLF Infotech Pvt. Ltd. Ethical Hacker, Vulnerability Assessment and Penetration Tester, Bug Hunter, Security Researcher, Optimistic, Philanthropist.

No responses yet