grthtrhthjhtyjytjytkergtrhtrjytjerhrfh4:24 29/09/2026Return-Path: Received: from adriana.servidorlinux11.com by adriana.servidorlinux11.com with LMTP id mH40LbEF0V9aRi0ASxZWHQ (envelope-from ); Wed, 09 Dec 2020 14:13:21 -0300 Return-path: Envelope-to: contact@zoe-uruguay.com Delivery-date: Wed, 09 Dec 2020 14:13:21 -0300 Received: from mail-il1-f169.google.com ([209.85.166.169]:39352) by adriana.servidorlinux11.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.93) (envelope-from ) id 1kn31l-00CRep-3H for contact@zoe-uruguay.com; Wed, 09 Dec 2020 14:13:21 -0300 Received: by mail-il1-f169.google.com with SMTP id q1so2269950ilt.6 for ; Wed, 09 Dec 2020 09:13:01 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=SCiLKxp3hChV7j9HK2Jfxi2E0ION1Jf2OKyH++/w3Ok=; b=ZPLYNw/wbZ2BCx3w4nK+xNJKGUJiB5e3+EbGhAWyBts9vsozYAi2YsCaQlXkkFmItK ex8arRB79VK4KzEuDS3k235DYZQiWrIqn2g9jkInOMZu8oan9NSvjSLo145jQBWDlucu oUzMdlp10/1SjrgIQaNxTiAZB6Wtj/zR9BObsY0bi2b0+z1FolcRdIo3zs77ruV3ZbM/ +fSco+pXXq+pv8KroOyhyCCdpxX8TWbwpf/+a7zRw9txvsfbt+ZgPHPJDsgZeuo5W3/9 cR8GjNk7XzhZmsAt4w0jnODHh1MTeU+IyYKo9bmHfuln+pWN6EO0DqWUeyfvUbjjQFyl 1HxQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=SCiLKxp3hChV7j9HK2Jfxi2E0ION1Jf2OKyH++/w3Ok=; b=rYY9GLkimXlaySigjm9Jo6kRs0exTBglKN2QMPate22q6Jei62xWpYIcDXngi9QI/+ 1z6DBl+nOREez2wEnIMGib2sa7/uovUoS2BQ7giwKe63/hK/c4zn+IMizD0oXuR4R1JC EKXfzi6jGWUPtgS4jOZ0vwqUMXP2rC4G+nxH21/SSl/NjAQVph+2h+AehvR3fUolY3VO 1o4yP+R2lO0hUD/qDXbLgut2Vq5+CjYtiynb9v1/sJVFYwABDnqRcnr/YX4sPLtCj6y0 CV+Y6zMtL7gIIeWAni9Uowsv5iwqCinUfvJqxlPECjwtzbnhIf3GoBGZG6CloDpu2vT6 9SxA== X-Gm-Message-State: AOAM530hUZBAZXQyq0MIK12ueulpL+aKxTg4YCitqCHMd/VdkNo7Z+Q/ CUZrRr9ldO1F8libJhif1vcpVVyAZeWXlr018FXs4qKWsNhEYw== X-Google-Smtp-Source: ABdhPJz3YsHfCW447YdaPto7xJgFvE97b1HdOp5DI+7TGt6WX2WO4k0/EC1RJvWqKZAlJOLuDH3unAhFLsmHUKCznX0= X-Received: by 2002:a92:41d2:: with SMTP id o201mr4308513ila.117.1607533960111; Wed, 09 Dec 2020 09:12:40 -0800 (PST) MIME-Version: 1.0 References: In-Reply-To: From: Meer Ramzan Date: Wed, 9 Dec 2020 22:12:28 +0500 Message-ID: Subject: Re: Bug Report To: contact@zoe-uruguay.com Content-Type: multipart/alternative; boundary="000000000000a82a3d05b60b2ab5" X-Spam-Status: No, score=0.9 X-Spam-Score: 9 X-Spam-Bar: / X-Ham-Report: Spam detection software, running on the system "adriana.servidorlinux11.com", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see root\@localhost for details. Content preview: Hello Team Is there any report on this bug? It's been a long time since I shared this issue, but I have not received a response from you I am hoping to receive a reward/service fee for the announcing of the vuln [...] Content analysis details: (0.9 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.8 BAYES_50 BODY: Bayes spam probability is 40 to 60% [score: 0.5000] 0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in digit [meerramzan199[at]gmail.com] -0.0 SPF_PASS SPF: sender matches SPF record 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider [meerramzan199[at]gmail.com] 0.0 HTML_MESSAGE BODY: HTML included in message 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain X-Spam-Flag: NO --000000000000a82a3d05b60b2ab5 Content-Type: text/plain; charset="UTF-8" Hello Team Is there any report on this bug? It's been a long time since I shared this issue, but I have not received a response from you I am hoping to receive a reward/service fee for the announcing of the vulnerability Furthermore, I might want to publish this on my blog for study purposes this week. Kind Regards On Wed, 7 Oct 2020 at 20:35, Meer Ramzan wrote: > Hi Team, > I am still waiting for your response. > Can you please let me know about the reported bug? > And I am hoping to receive a reward for the responsible disclosure of the > vulnerability. > > Kind Regards, > > On Sat, 19 Sep 2020 at 22:35, Meer Ramzan wrote: > >> Hello Team , >> >> >> >> I am a security researcher and I founded this vulnerability in your >> website. >> >> I just sent a forged email to my email that appears to originate from >> contact@zoe-uruguay.com >> . I was able to do this because of the following DMARC record: >> >> >> >> DMARC record lookup and validation for your website >> >> "No DMARC Record found" >> >> >> >> Fix: >> >> 1)Publish DMARC Record. >> >> 2)Enable DMARC Quarantine/Reject policy >> >> 3)Your DMARC record should look like >> >> "v=DMARC1; p=reject; pct=100; ri=86400; rua=mailto:info@domain.com" >> >> >> >> This is useful in phishing, and this type of vulnerability is newsworthy ( >> http://bits.blogs.nytimes.com/2015/04/09/sendgrid-email-breach-was-used-to-attack-coinbase-a-bitcoin-exchange/ >> ). >> >> >> >> This can be done using any php mailer tool like this , >> >> > >> $to = "VICTIM@example.com"; >> >> $subject = "Password Change"; >> >> $txt = "Change your password by visiting here - [VIRUS LINK HERE]l"; >> >> $headers = "From: >> contact@zoe-uruguay.com >> >> "; >> >> mail($to,$subject,$txt,$headers); >> >> >> >> ?> >> >> >> >> You can check your DMARC record form here : >> https://mxtoolbox.com/SuperTool.aspx >> >> >> >> Reference : >> https://www.knownhost.com/wiki/email/troubleshooting/setting-up_spf-dkim-dmarc_records >> >> >> >> Let me know if you need me to send another forged email, or if you have >> any other questions. >> >> >> I hope to receive reward for the responsible disclosure of the >> vulnerability >> >> >> Thanks, >> >> Regards >> > --000000000000a82a3d05b60b2ab5 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Hello Team

Is there any report on this bug? It'= s been a long time since I shared this issue, but I have not received a res= ponse from you
I am hoping to receive a reward/service fee for the annou= ncing of the vulnerability
Furthermore, I might want to publish this on = my blog for study purposes this week.

Kind Regards=C2=A0
On Wed, = 7 Oct 2020 at 20:35, Meer Ramzan <meerramzan199@gmail.com> wrote:
Hi Team,
I am still waiting= for your response.
Can you please let me know about the reported bug?And I am hoping to receive a reward for the responsible disclosure of the= vulnerability.

Kind Regards,

On Sat, 19 Sep 2020 at 22:35, Meer= Ramzan <me= erramzan199@gmail.com> wrote:

Hello Team ,

=C2=A0=

I am a security researcher= and I founded this vulnerability in your website.

I just sent a forged email to my email=C2=A0that ap= pears to originate from=C2=A0

=

contact@zoe-uruguay.com

=

. I was able to do this because of the following D= MARC record:

=C2=A0

DMARC record lookup and validatio= n for your website

"No= DMARC Record found"

= =C2=A0

Fix:

1)Publish DMARC Record.

2)Enable DMARC Quarantine/Reject policy

3)Your DMARC record should look = like

"v=3DDMARC1; p=3D= reject; pct=3D100; ri=3D86400; rua=3Dmailto:info@domain.com"

=C2=A0

This is useful in phishing, and this type of vulnerability is newsworthy (= http://bi= ts.blogs.nytimes.com/2015/04/09/sendgrid-email-breach-was-used-to-attack-co= inbase-a-bitcoin-exchange/).

=C2=A0

This can be do= ne using any php mailer tool like this ,

<?php

$to = =3D "VICTIM@ex= ample.com";

$subje= ct =3D "Password Change";

$txt =3D "Change your password by visiting here - [VIRUS LINK= HERE]l";

$headers =3D= "From:=C2=A0

contact@zoe-uruguay.com

<= h3 style=3D"overflow:hidden;white-space:nowrap;font-size:0.75rem;font-weigh= t:inherit;margin:inherit;text-overflow:ellipsis;font-family:Roboto,RobotoDr= aft,Helvetica,Arial,sans-serif;letter-spacing:0.3px;color:rgb(95,99,104);li= ne-height:20px">

=

";

mail($to,$subject,$txt,$headers);

=C2=A0

?>

=C2=A0

You can check your DMARC rec= ord form here :=C2=A0https://mxtoolbox.com/SuperTool.aspx

=C2=A0

Reference :=C2=A0https://w= ww.knownhost.com/wiki/email/troubleshooting/setting-up_spf-dkim-dmarc_recor= ds

=C2=A0

Let me know if you need me to send ano= ther forged email, or if you have any other questions.


I hope to receive reward for the responsible disclosure of the vulner= ability=C2=A0


Thanks,

Regards

--000000000000a82a3d05b60b2ab5--