Talk Marcello Salvati

Spamchannel: spoofing emails from 2 million+ domains – while also »bypassing« SPF & DMARC


DESCRIPTION

Tired of your phishing emails not landing in your targets inbox?
Ever wanted to send an email as the mayor of Boston?
Too lazy to use your laptop and wish you could just spoof emails from your phone?

If yes, then you've come to the right place!

In this talk, I'll be showing how you can spoof emails from 2M+ domains while also "bypassing" SPF & DMARC by (ab)using an existing partnership between Cloudflare and an extremely sus transactional email provider: we'll be diving deep into "edge" serverless applications and the magical world of email security where everything is held up by duct tape and banana peels.


WHY THE COMMITTEE CHOSE THIS TALK

Marcello is one of the most active members of the Twitter Security community with >27k followers. He came up with some awesome tools for redteamers and is one of the most prominent members of our community. We look forward to his talk delivering some real world insights in to attack techniques.


Share by: