• 0 Posts
  • 36 Comments
Joined 4 years ago
cake
Cake day: December 20th, 2021

help-circle








  • They found a way to inject text into a google email notification (by setting the name of their google workspace account to the phishing message), and then set up a mail forwarding service to redirect the notification to the victim accounts. That way the victims receive a legit email from google but the text of the email is attacker-controlled and can point the victim to their phishing site.

    It’s not really a vulnerability in DKIM. The bug is in google’s use of attacker-controlled text fields in their notification emails.