Collected research
Composition Kills: 18 Attacks on Email Sender Authentication
Composition Kills: A Case Study of Email Sender Authentication
Inconsistent message parsing between the components of email systems lets attackers bypass SPF, DKIM, and DMARC to impersonate arbitrary senders and forge DKIM-signed mail with a legitimate site's signature. Manual analysis plus black-box fuzzing found 18 evasion techniques that worked against 10 email providers and 19 clients, all vulnerable.
Record
- Document
- Composition Kills: A Case Study of Email Sender Authentication
- Researcher
- Jianjun Chen, Vern Paxson and Jian Jiang
- Published by
- usenix.org
- Topic
- Identity
In the archive
Related sources
- Tool Repository
- Paper project page
- You have No Idea Who Sent that Email: 18 Attacks on Email Sender Authentication
- USENIX Security '20 - Composition Kills: A Case Study of Email Sender Authentication
Tags
This page is the archive's own catalogue record. The research is the work of Jianjun Chen, Vern Paxson and Jian Jiang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .