Guest User

Bone

a guest
Dec 31st, 2014
270
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. Paybase.com insecurely sends emails from it's main webserver (Your supposed to send emails from a separate dedicated email server or strip out the origin IP address). In the email header, the server's IP address is revealed..
  2.  
  3. Received: from [127.0.0.1] (Unknown [23.253.245.68]) by mxa.mailgun.org with
  4. ESMTP id XXXXXXXXXXXXXX; Wed, 31 Dec 2014 01:00:00 -0000 (UTC)
  5. Content-Type: text/html; format="flowed"
  6. From: PayBase <support@paybase.com>
  7.  
  8. 23.253.245.68 = paybase.com
  9.  
  10. https://23.253.245.68
  11. This bypasses the WAF that paybase.com uses provided by Cloudflare.
RAW Paste Data