Bugtraq mailing list archives
Re: I found this today and iam reporting it to you first!!! (fwd)
From: dulitz () VALLEYTECH COM (Daniel Dulitz)
Date: Sat, 4 Sep 1999 11:25:41 -0400
Technical Incursion Countermeasures writes:
basically find two sites whose FW is conf'd to accept all mail and forward it to the real mailserver. If this mailserver bounces invalid addresses then you're on your way... spoof a mail from an invalid address on one end to an invalid address on the other. and sit back..
Sit back and watch absolutely nothing happen, unless both mailers are misconfigured. Even the venerable RFC821 (http://www.faqs.org/rfcs/std/std10.html) notes that: Of course, server-SMTPs should not send notification messages about problems with notification messages.
the first site will accept the mail (this is the fault - it should reject if it is to comply with the IETF standard)
This cannot be the fault -- otherwise any pair of SMTP servers who happen to send mail to each other by way of a relay (an ordinary MX relay) would be vulnerable to such a spoofing attack. Best, daniel dulitz
Current thread:
- I found this today and iam reporting it to you first!!! (fwd) Alfred Huger (Aug 30)
- <Possible follow-ups>
- Re: I found this today and iam reporting it to you first!!! (fwd) blue0ne (Sep 02)
- Re: I found this today and iam reporting it to you first!!! (fwd) Technical Incursion Countermeasures (Sep 02)
- [SECURITY] TenFour TFS SMTP 3.2 Buffer Overflow Christophe Lesur (Sep 02)
- SCO 5.0.5 /bin/doctor local root comprimise Brock Tellier (Sep 03)
- Re: SCO 5.0.5 /bin/doctor local root comprimise Seth R Arnold (Sep 08)
- Re: I found this today and iam reporting it to you first!!! (fwd) Peter van Dijk (Sep 04)
- Re: I found this today and iam reporting it to you first!!! (fwd) Daniel Dulitz (Sep 04)
- Re: I found this today and iam reporting it to you first!!! (fwd) Bret Watson (Sep 07)
- Re: I found this today and iam reporting it to you first!!! (fwd) Daniel W. Dulitz x108 (Sep 06)
- Re: I found this today and iam reporting it to you first!!! (fwd) Wietse Venema (Sep 04)
- Re: I found this today and iam reporting it to you first!!! (fwd) Alan Brown (Sep 07)
- Re: I found this today and iam reporting it to you first!!! (fwd) Jamie A. Lawrence (Sep 04)
- Re: I found this today and iam reporting it to you first!!! (fwd) Bret Watson (Sep 07)
- Re: I found this today and iam reporting it to you first!!! (fwd) Bill Royds (Sep 07)