centrifuge / security

Security bounty & audit overview of Centrifuge
MIT License
2 stars 2 forks source link

Centrifuge - #1 Vulnerability Report (Missing DMARC Record) #2

Open roony0072 opened 5 years ago

roony0072 commented 5 years ago

Dear Team,

I found an weak spot on your website.

Vulnerability Name: Missing DMARC Record

Vulnerable URL: centrifuge.io

Email spoofing is possible due to missing DMARC Records.

Due to this Server Security Misconfiguration > Mail Server Misconfiguration > Email Spoofing to Inbox due to Missing or Misconfigured DMARC on Email Domain.

To check DMARC record. Link: https://mxtoolbox.com/DMARC.aspx

As said by you for DMARC you don't want to reject any messages you can set 'P=None' DMARC

Attached screenshot for your reference. centrifugeDMARC

Regards, Rohan Patil