Anatomy of a Facebook-Hosted Phishing Attack

here’s a small hint as to why the three aforementioned headers that are optional are utilized by the leafmailer script in question. it’s called an oversight by an unskilled attacker whom has no clue whatsoever about the emailer script utilizing these headers and thus disclosing their shit phishing attempts. not exactly sure how you could miss this when you’ve pretty much covered all the other bases in your post

