Email Injection

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
4,128
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Jun 16, 2009

Now that I finally got rid of WP-Forum, I can show you guys an Email Injection flaw that existed in that forum. An Email Injection flaw occur when a form is added to a web page that submits data to an email application, and user input is not filtered properly. A malicious user can exploit the MIME format to append additional information to the message being sent. This is possible because the MIME format uses a carriage return to delimit the information in a message. Adding carriage returns to submitted form data can allow an email application to be used to send thousands of messages at once. A spammer could exploit this to send large numbers of messages anonymously.

Category:

Howto & Style

Tags:

License:

Standard YouTube License

  • likes, 0 dislikes

Link to this comment:

Share to:

Top Comments

  • Love this, do you know if its a common security flaw in forums?

  • holyshit !

    i love your videos

see all

All Comments (8)

Sign In or Sign Up now to post a comment!
  • It is almost certainly a flaw with a lot of things other than forums; I dare say things like adobe flash player can be interfered with by some method along similar lines - as some of my recent experiences on a certain video blogging site seem to strongly indicate. And yeah, this comment is for the benefit of a number of specific individuals.

  • Holy crap, this is awesome!

  • maybe malicious html code, or anything allowed in normal email messages. otherwise, i don't believe so.

    Not sure about the attachments.

  • can you use this to inject "virus" scripts on an email client that doent allow scripts? like writing a code in the "message" field and the client will still send the mail.

    and is it possible to attach something u wouldnt normally be allowed to?

    anyway thanks i luv your videos :)

  • Too Cool.

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more