In this video walkthrough, we went through a common web application security issue found in contact forms on any website. This security issue allows for the insertion of certain characters and commands that create a copy of every email and inquiry without the website administrator’s knowledge. We used bWAPP from OWASP to demonstrate this.

Skills Learned

  • bWAPP
  • Mail Header Injection

