Facebook message spoofing via SMTP
Summary
Facebook's mail server accepted inbound email based only on a valid PTR record, letting attackers spoof external-domain senders and deliver phishing or malware to @facebook.com addresses.
- Published
- Collected
Skip to content