The Web Application Security Consortium is proud to present MX Injection: Capturing and Exploiting Hidden Mail Servers. This article discusses how an attacker can inject additional commands into an online web mail application communicating with an IMAP/SMTP server.