📜 ⬆️ ⬇️

XSS in mail.ru?

Just now, my mother received a letter in the mail, with the subject “Locking your account”.
Naturally, she told me about it. In order not to be distracted much from his affairs, he quickly set up her account in evolution and received letters. Opened the letter and saw in the body "<< script"
Opened the source text of the letter, and that's what he saw there:
From bezotveta@odnoklassniki.ru Sat Sep 25 17:11:07 2010
Return-path: <visss@srv10-h-st.jino.ru>
Received: from [] (port=49915 helo=srv10-h-st.jino.ru) by
mx84.mail.ru with esmtp id 1OzUWx-0001zQ-00 for s**@list.ru;
Sat, 25 Sep 2010 17:11:07 +0400
Received-SPF: none (mx84.mail.ru: is neither permitted nor
denied by domain of srv10-h-st.jino.ru) client-ip=;
envelope-from=visss@srv10-h-st.jino.ru; helo=srv10-h-st.jino.ru;
X-Mru-BL: 0:0:0
X-Mru-PTR: srv10-h-st.jino.ru
X-Mru-NR: 1
X-Mru-OF: Linux (ethernet/modem)
X-Mru-RC: RU
Received: by srv10-h-st.jino.ru (Postfix, from userid 2108) id E4189D44160;
Sat, 25 Sep 2010 17:11:06 +0400 (MSD)
To: s***@list.ru
MIME-Version: 1.0
Content-type: text/html; charset="UTF-8"
X-Priority: 3 (Normal)
From: =?UTF-8?Q?=D0=9E=D0=B4=D0=BD=D0=BE=D0=BA=D0=BB=D0=B0=D1=81=D1=81=D0=BD=D0=B8=D0=BA=D0=B8_?= <bezotveta@odnoklassniki.ru>
Message-ID: <172562218.20100925171057@592537083920>
Date: Sat, 25 Sep 2010 17:11:06 +0400 (MSD)
X-Spam: Not detected
X-Mras: Ok
X-Evolution-Source: pop://s***@pop.list.ru/
Content-Transfer-Encoding: 8bit



Source: https://habr.com/ru/post/104971/

All Articles