Web Hack List

Top 10 winner

SMTP Smuggling - Spoofing E-Mails Worldwide

Outbound and inbound SMTP servers disagree on which byte sequence ends message data, so a sequence such as LF dot CRLF passes one server unfiltered and is read as end-of-data by the next. An attacker with any account at an affected provider can smuggle a second, entirely forged message that inherits the provider's IP and so passes SPF, DKIM alignment and DMARC.

Record

Researcher
Timo Longin
Published by
SEC Consult
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Timo Longin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .