RainLoop / rainloop-webmail

Simple, modern & fast web-based email client
http://rainloop.net
MIT License
4.1k stars 890 forks source link

RainLoop affected by Mailsploit #1591

Open BuZZ-dEE opened 6 years ago

BuZZ-dEE commented 6 years ago

https://www.mailsploit.com/

ervee commented 6 years ago

Someone reported it there but it is not confirmed. Did you confirm it? Has anyone disclosed the issue to @RainLoop? Or are you just thinking out loud?

xf- commented 6 years ago

@ervee tested it with test utility from mailsploit.com and @RainLoop is also listed in Google Docs.

BuZZ-dEE commented 6 years ago

Yes, I can confirm it. I also tested it with test utility from mailsploit.com.

ervee commented 6 years ago

Okay. So far as I can tell this is a GUI sort-of-bug. The "From:" header used to display the e-mail source has always been easy to manipulate. This "bug" just adds the capability to circumvent SPF/DMARC if you have it configured in your MTA in the first place.

I don't know if there is anything @RainLoop can do about this but he can try. I actually agree with Mozilla in their statement that this is to be fixed by the MTA. Not by the MUA.

msberends commented 5 years ago

Check the link; not affected anymore. Issue can be closed.