How hackers spoof your email address

Поділитися
Вставка
  • Опубліковано 26 вер 2024
  • Email spoofing is possible by forging email syntax in several methods of varying complexity.
    In this video we will identify email spoofing vulnerability and we will demonstrate the spoofing is done and precautionary measure to put in place to avoid spoofing of your domain.
    Email spoofing Analysis and Detection
    • Play it Safe: Recogniz...
    Connect with me across various interactive platforms for a dynamic and connected experience.
    🔗Discord:
    / discord
    🔗 Social Media:
    X (twitter) : @r007User
    Facebook : / ctfsec
    📺 Twitch
    / ctfsec
    🌐 Website:
    r007us3r.githu...
    🎥 UA-cam Channels:
    / @ctf-sec
    📧 Business Inquiries:
    ctfsec001@gmail.com
    👇 Other Links:
    t.me/+VpUp7Bxq...
    Support me
    [+] Buymeacoffee
    paystack.com/p...
    Telegram
    t.me/+VpUp7Bxq...
    #hacking #captureflag #capturetheflag #google #informationexposure #informationdisclosure #ctfsec #ctfsecurity #ethicalhacking #hacking #cybersecurity #hacker #hackers #kalilinux #linux #ethicalhacker #programming #infosec #security #pentesting #hackingtools #technology #hack #informationsecurity #cybercrime #coding #cybersecurityawareness #malware #python #cyberattack #cyber #hacked #computerscience #hackerman #programmer #tech #or #anonymous #hackerspace #cybersecuritytraining #hackingnews #secutiy #bugbounty #datasecurity #learnhacking #hackinginstagram #ransomware #termux #termuxhacking #privacy #informationtechnology #ethicalhackers #dataprotection #hackerindonesia #computer #hackernews #phishing #java #coder #developer #blackhathacker #growthhacking #metasploit #exploit #hacks #it #wifihacking

КОМЕНТАРІ • 60

  • @JamieLokken-t2g
    @JamieLokken-t2g 9 місяців тому +1

    Please, how do it download and install the SendEmail terminal for me to move further ? thank you

    • @ctf-sec
      @ctf-sec  9 місяців тому +1

      It called Kali Linux and here is how it can be installed
      ua-cam.com/video/BzH9B97Qupg/v-deo.htmlsi=w0sgRnmWzVWT-5Vc

  • @bolajiishola-rl7zv
    @bolajiishola-rl7zv Рік тому +1

    The video make it easier than I thought. Is sendemail available on windows operating system?

    • @ctf-sec
      @ctf-sec  Рік тому

      Here is a github repo to get sendemail github.com/mogaal/sendemail
      Remember sendemail is written in perl. You can also grab exe version of send email with just a simple google search.

    • @hawaiihawaii1112
      @hawaiihawaii1112 Рік тому

      Be'cos you snd to the email you use nd registered sendinblue that's why it went to inbox

    • @ctf-sec
      @ctf-sec  Рік тому

      ​​@@hawaiihawaii1112 It has been tested on other email same result. One good thing about sendinblue it is hardly detected as spam.

  • @thomas-zh3mz
    @thomas-zh3mz 10 місяців тому +1

    Quick question ,what's the method you used to obtain the email html with the jumia headers and singnatures, im having trouble finding online how to clone original emails.
    Btw your demonstration for this video was good , thank you so much !

    • @ctf-sec
      @ctf-sec  10 місяців тому

      In Gmail, you can view the HTML code of an email by opening the email, clicking the three dots in the upper-right corner of the email window, and selecting "Show original" from the menu. This will open a new tab or window with the raw content of the email, including the HTML code.

    • @thomas-zh3mz
      @thomas-zh3mz 10 місяців тому

      @@ctf-sec i got it now , bless your heart for still replying to people after 8 months ,have a good day !

    • @thomas-zh3mz
      @thomas-zh3mz 10 місяців тому

      @@ctf-sec when i came to test it out on code pen ,it showed me bugged emails .the initial time i saw cloning emails was done by uploading the headers and typing out the contents of the email inside gmail . thats what i was searching for all along , a simple ("educational purposes" ) but i thought it would be a popular topic on the internet but i was wrong .

  • @jermahmapetia5747
    @jermahmapetia5747 Рік тому

    Bro abeg i no understand it much. I wan learn from you bro

    • @ctf-sec
      @ctf-sec  Рік тому

      Kindly subscribe to be notified when other videos are uploaded.

  • @darkhunter-px8uk
    @darkhunter-px8uk 3 місяці тому

    It says, email sent successfully but the email never arrives into the inbox

    • @ctf-sec
      @ctf-sec  3 місяці тому

      What email server did you use?

    • @darkhunter-px8uk
      @darkhunter-px8uk 3 місяці тому

      @@ctf-sec I used Brevo's SMTP Relay server

  • @harshgupta1911
    @harshgupta1911 3 місяці тому

    Not working know if manipulating from address

    • @unoproject20
      @unoproject20 2 місяці тому +1

      I used to be able to do this technique, now I can't.

    • @ENGCY-Mir
      @ENGCY-Mir Місяць тому

      ​@@unoproject20same here, did u find any alternative smtp server that works?

  • @zeephisher5567
    @zeephisher5567 Рік тому +1

    hey, how do I change the output to look like my prefered sender and to also make it look exactly the same?

    • @ctf-sec
      @ctf-sec  Рік тому

      Not sure I understand the first part but for the second you need basic HTML/CSS for that.

    • @lameshithead
      @lameshithead 7 місяців тому

      little scammer. get a job. but i guess not as frontend-dev xD

  • @sahilathwal1314
    @sahilathwal1314 27 днів тому

    it says email sent successfully but i didn't receive any email and i am using smtp brevo server

    • @ctf-sec
      @ctf-sec  25 днів тому

      Try using a different email server.

  • @strictlyirving498
    @strictlyirving498 Рік тому +2

    You never dropped spoof check link though?

    • @ctf-sec
      @ctf-sec  Рік тому +2

      Thank you it will be added to the video description mean while here is the github link github.com/a6avind/spoofcheck

  • @0RIPPER0
    @0RIPPER0 8 місяців тому

    Is sendinblue free to login or we have to buy premium or something?

    • @ctf-sec
      @ctf-sec  8 місяців тому

      It has premium versions but at the time of recording it is free for using Email Server.

    • @0RIPPER0
      @0RIPPER0 8 місяців тому

      @@ctf-sec is it free now ? For SMTP server

  • @anmolsargam7204
    @anmolsargam7204 Рік тому

    I am getting error of Hostname verification failed. I would appreciate it if you can help out a fellow brother

    • @ctf-sec
      @ctf-sec  Рік тому

      Where exactly are you getting the error you can drop the full screenshot of the error on the Telegram Channel in the description box

    • @momohcharles7811
      @momohcharles7811 Рік тому

      I also have the same error message. How do I fix it?

    • @ctf-sec
      @ctf-sec  Рік тому

      @@momohcharles7811 Sendinblue is currently experiencing TLS issues after transitioning to brevo will drop an update if I have a possible fix to the problem.

  • @zahraaal-mubarak6104
    @zahraaal-mubarak6104 11 місяців тому

    What is the technique called?

    • @ctf-sec
      @ctf-sec  11 місяців тому

      Email spoofing

  • @strickit178
    @strickit178 9 місяців тому

    hey, does this still work with sendinblue?

    • @ctf-sec
      @ctf-sec  9 місяців тому

      Sendinblue is now called brevo and regarding if it still works I haven't tried it lately you can try it and give a feedback.

    • @0RIPPER0
      @0RIPPER0 8 місяців тому

      Is it free ?

    • @gaminggeek4637
      @gaminggeek4637 2 місяці тому

      @@ctf-sec no its not working see the error from sendinblue.Sending has been rejected because the sender you used is not valid. Validate your sender or authenticate your domainValidate your sender or authenticate your domain

    • @ENGCY-Mir
      @ENGCY-Mir Місяць тому

      ​@@gaminggeek4637yeah, did u find any alternative?

  • @KakiSudan
    @KakiSudan 9 місяців тому

    When the target replies your spoofed email how do you receive reply in your personal inbox?

    • @ctf-sec
      @ctf-sec  9 місяців тому

      The attacker manipulates headers to direct replies to their own email address, allowing them to receive responses in their personal inbox directly.

    • @Ashish_painuly
      @Ashish_painuly 3 місяці тому

      @@ctf-sec can you please explain how to do that? My idea is that: you place Reply-To tag with a receiving email on the header. Then any reply of receipt can be received on attacker's email (which is there under Reply-To tag). Is that correct?

    • @ctf-sec
      @ctf-sec  3 місяці тому

      @@Ashish_painuly You are absolutely correct, Attackers manipulate spoof emails by forging the "From" address and setting a custom "Reply-To" header to receive replies.

  • @TheKiddie1-it9dl
    @TheKiddie1-it9dl 10 місяців тому

    how could you bypass SPF and DKIM. both authentication method is using to prevent email spoof. you sent the email from different server. the receiver mail server supposed to check the right sender server address.

    • @ctf-sec
      @ctf-sec  10 місяців тому +1

      Yes the receiving mail server checks if the mail came from the domain it claims and then assign pass or failed status to it and might choose to quarantine based on the policies in the server.

  • @work-n3h
    @work-n3h 2 місяці тому

    repo link

    • @ctf-sec
      @ctf-sec  2 місяці тому

      github.com/BishopFox/spoofcheck

  • @alibilal7190
    @alibilal7190 Рік тому

    Ia am getting error hostname verification failed tls failed can you solve this problem

    • @ctf-sec
      @ctf-sec  Рік тому

      There is currently a bug in the sendemail tool which hasn't been fixed yet, here is more information www.reddit.com/r/Kalilinux/comments/15h4bz6/sendemail_tool_doesnt_work/

  • @wanisarameelap9465
    @wanisarameelap9465 3 місяці тому

    Why is it whenever i hear without further ado, there is always further ado. If you want to stretch your video out so you can make more money, then be honest and say thats what you are doing. Either way i am going to give you a dislike and turn off the video.

    • @ctf-sec
      @ctf-sec  3 місяці тому

      Thank you for your constructive feedback

  • @g_clinch
    @g_clinch Рік тому +1

    CAN IT WORK WITH TERMUX

    • @ctf-sec
      @ctf-sec  Рік тому

      Sendmail will work, what you would need is a good email server and a vulnerable domain as explained in the video

  • @melindereynalds7474
    @melindereynalds7474 Рік тому +1

    👌 'promosm'