oss-sec mailing list archives
Re: Re: New SMTP smuggling attack
From: Stuart D Gathman <stuart () gathman org>
Date: Fri, 22 Dec 2023 13:42:49 -0500 (EST)
On Sat, 23 Dec 2023, Alexander E. Patrakov wrote:
I'm trying to make sense of it - where's the compromise of the Confidentiality, Integrity or Availability of the affected mail servers?The integrity of the sender's identity, as a minimum, is compromised here. Normally, when relaying mail, servers add a "Received:" header that specifies where they received the connection from. This allows tracking down the true origin of the message. The smuggled message does not have such a header and thus misrepresents the vulnerable relay as the ultimate sender. Additionally, if the relay has destination-based deny lists that deny some but not all addresses on the destination domain, they are sidestepped.
This is certainly a bug, but the currently reality is that authentication involves SPF, DKIM, and other schemes - and does not solely rely on headers. So can this "delete some headers" attack compromise these authentication schemes? I don't have a PoC, but I think so. If the original sender can indeed convince the victim to relay their message, the victim will sign it using their DKIM key - missing header fields and all. Relays will typically alter the MAIL FROM so that SPF authentication passes. But, that first "If" is the kicker. Any mail admin these days is very careful about who can relay through their server. If they are relaying at all, it is for a customer, partner, or buddy.
Current thread:
- New SMTP smuggling attack Marcus Meissner (Dec 21)
- Re: New SMTP smuggling attack Claus Assmann (Dec 21)
- Re: Re: New SMTP smuggling attack Marcus Meissner (Dec 22)
- Re: Re: New SMTP smuggling attack Stuart Henderson (Dec 22)
- Re: Re: New SMTP smuggling attack Marcus Meissner (Dec 22)
- Re: Re: New SMTP smuggling attack Erik Auerswald (Dec 22)
- Re: Re: New SMTP smuggling attack Rodrigo Freire (Dec 22)
- Re: Re: New SMTP smuggling attack Alexander E. Patrakov (Dec 22)
- Re: Re: New SMTP smuggling attack Erik Auerswald (Dec 22)
- Re: Re: New SMTP smuggling attack Stuart D Gathman (Dec 22)
- Re: Re: New SMTP smuggling attack Harry Sintonen (Dec 22)
- Re: Re: New SMTP smuggling attack Marcus Meissner (Dec 22)
- Re: New SMTP smuggling attack Claus Assmann (Dec 21)
- Re: Re: New SMTP smuggling attack Bjoern Franke (Dec 22)
- Re: Re: New SMTP smuggling attack Valtteri Vuorikoski (Dec 23)
- Re: Re: New SMTP smuggling attack Marcus Meissner (Dec 24)
- Re: Re: New SMTP smuggling attack kai (Dec 25)
- Re: New SMTP smuggling attack Claus Assmann (Dec 26)
- Re: Re: New SMTP smuggling attack Alan Coopersmith (Dec 29)
- Re: Re: New SMTP smuggling attack Marcus Meissner (Dec 30)
- Re: Re: New SMTP smuggling attack Claus Assmann (Dec 30)