Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Other Discussions
  3. The Insider News
  4. Security bug allows anyone to spoof Microsoft employee emails

Security bug allows anyone to spoof Microsoft employee emails

Scheduled Pinned Locked Moved The Insider News
comsecurityhelp
5 Posts 5 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K Offline
    K Offline
    Kent Sharkey
    wrote on last edited by
    #1

    Techcrunch[^]:

    A researcher has found a bug that allows anyone to impersonate Microsoft corporate email accounts, making phishing attempts look credible and more likely to trick their targets.

    Good thing they never email anyone

    "The bug, according to Kokorin, only works when sending the email to Outlook accounts." <-- Oh, phew. Good thing no one uses those. /sigh... Microsoft...

    J M C 3 Replies Last reply
    0
    • K Kent Sharkey

      Techcrunch[^]:

      A researcher has found a bug that allows anyone to impersonate Microsoft corporate email accounts, making phishing attempts look credible and more likely to trick their targets.

      Good thing they never email anyone

      "The bug, according to Kokorin, only works when sending the email to Outlook accounts." <-- Oh, phew. Good thing no one uses those. /sigh... Microsoft...

      J Offline
      J Offline
      jochance
      wrote on last edited by
      #2

      Did something change? I was of the impression you could forge email headers all you wanted so long as you controlled the SMTP sending the mail? I've sent prank mail from Gates and such. From .NET it was as simple as changing the FROM: to whatever you want.

      O 1 Reply Last reply
      0
      • J jochance

        Did something change? I was of the impression you could forge email headers all you wanted so long as you controlled the SMTP sending the mail? I've sent prank mail from Gates and such. From .NET it was as simple as changing the FROM: to whatever you want.

        O Offline
        O Offline
        obermd
        wrote on last edited by
        #3

        I suspect this bug allows you to spoof the entire header, including the routing and source mail server information. Changing the "FROM" information doesn't change the source email server information.

        1 Reply Last reply
        0
        • K Kent Sharkey

          Techcrunch[^]:

          A researcher has found a bug that allows anyone to impersonate Microsoft corporate email accounts, making phishing attempts look credible and more likely to trick their targets.

          Good thing they never email anyone

          "The bug, according to Kokorin, only works when sending the email to Outlook accounts." <-- Oh, phew. Good thing no one uses those. /sigh... Microsoft...

          M Offline
          M Offline
          Mark Starr
          wrote on last edited by
          #4

          Huh. I thought most of them use GMail… :laugh:

          Time is the differentiation of eternity devised by man to measure the passage of human events. - Manly P. Hall Mark Just another cog in the wheel

          1 Reply Last reply
          0
          • K Kent Sharkey

            Techcrunch[^]:

            A researcher has found a bug that allows anyone to impersonate Microsoft corporate email accounts, making phishing attempts look credible and more likely to trick their targets.

            Good thing they never email anyone

            "The bug, according to Kokorin, only works when sending the email to Outlook accounts." <-- Oh, phew. Good thing no one uses those. /sigh... Microsoft...

            C Offline
            C Offline
            charlieg
            wrote on last edited by
            #5

            this is an oxymoron type of email, right? And the US Senate is upset with MS getting in bed with the CCP?

            Charlie Gilley “They who can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety.” BF, 1759 Has never been more appropriate.

            1 Reply Last reply
            0
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Don't have an account? Register

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • World
            • Users
            • Groups