Top 10 winner
SMTP Smuggling - Spoofing E-Mails Worldwide
Outbound and inbound SMTP servers disagree on which byte sequence ends message data, so a sequence such as LF dot CRLF passes one server unfiltered and is read as end-of-data by the next. An attacker with any account at an affected provider can smuggle a second, entirely forged message that inherits the provider's IP and so passes SPF, DKIM alignment and DMARC.
Record
- Researcher
- Timo Longin
- Published by
- SEC Consult
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Timo Longin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .