Bugtraq mailing list archives
Re: Web Tool Announcement: ismymailsecure.com
From: Kari Hurtta <hurtta+bugtraq () leija mh fmi fi>
Date: Wed, 25 Aug 2010 12:30:17 +0300 (EEST)
Holger Rabbach <hrabbach () crossroad-networks com>: (Wed Aug 25 11:39:07 2010) [ Charset ISO-8859-1 converted... ]
Hi Kari, it does not - yet. This is actually what I'm working on at the moment. However, since most MTAs at the moment don't do this kind of check, it is not very useful. So the tool currently only checks for encryption capabilities, it does *not* check for protection against MiTM attacks. The next, enhanced version of the tool will have an optional check for this and also the supported ciphers. Holger
And because mail server name and email address does not need to be any connection also checking of signature of certificate agaist CA does not help much. It does not protect attack agaist MX records on DNS.
On 25/08/2010 09:59, Kari Hurtta wrote:Holger Rabbach <hrabbach () crossroad-networks com>: (Wed Aug 18 12:59:19 2010) [ Charset ISO-8859-1 converted... ]Dear Bugtraq community, I am happy to announce the immediate availability of a web based email security testing tool at http://www.ismymailsecure.com. The tool is an end-user friendly way to determine if the mail servers for a certain email address support the STARTTLS capability to encrypt the email transfer between servers. While most email providers have frontends that use encryption, the actual email transfers via SMTP are often not secureIt seems not check if certificate returned is signed by trusted CA.
/ Kari Hurtta
Current thread:
- Web Tool Announcement: ismymailsecure.com Holger Rabbach (Aug 18)
- Re: Web Tool Announcement: ismymailsecure.com Chuck Swiger (Aug 23)
- Re: Web Tool Announcement: ismymailsecure.com Kari Hurtta (Aug 25)
- Re: Web Tool Announcement: ismymailsecure.com Holger Rabbach (Aug 25)
- Re: Web Tool Announcement: ismymailsecure.com Kari Hurtta (Aug 25)
- Re: Web Tool Announcement: ismymailsecure.com Holger Rabbach (Aug 25)
- Re: Web Tool Announcement: ismymailsecure.com Tim (Aug 25)
- Re: Web Tool Announcement: ismymailsecure.com Brian Behlendorf (Aug 26)
- Re: Web Tool Announcement: ismymailsecure.com Holger Rabbach (Aug 25)
- Re: Web Tool Announcement: ismymailsecure.com Tim (Aug 25)