digitalcourage.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Diese Instanz wird betrieben von Digitalcourage e.V. für die Allgemeinheit. Damit wir das nachhaltig tun können, erheben wir einen jährlichen Vorausbeitrag von 1€/Monat per SEPA-Lastschrifteinzug.

Server stats:

849
active users

#smtpsmuggling

0 posts0 participants0 posts today
Replied in thread

I understand SEC's perspective. "We've told that central global organization that is super experienced in managing large scale security issues, they've told the vendors, but apparently nobody thinks this is a big deal, so yeah, let's publish the blog post then."

So, if what SEC says is true, then CERT/CC has fucked up. But of course SEC could've also talked to Postfix on their own. But why would they, CERT/CC already did.

This was all a big dumb game of telephone, it seems.

Continued thread

Im Juni wird eine Sicherheitslücke entdeckt: Die zur Mailauslieferung notwendige "Zusammenarbeit" zwischen Mailservern lässt sich austricksen, um falsche Absender unterzujubeln. So wird #Spam und #Phishing Tür und Tor geöffnet.

Die Entdecker wissen von 11 Systemen (Mailprovider, Softwarehersteller), die betroffen sind. Informieren aber nur 3 davon. Ein Versuch der Klärung der Hintergründe vor dem #37C3-Vortrag heute.
#SMTPSmuggling
📰 dnip.ch/2023/12/22/nicht-wirkl
🧵 waldvogel.family/@marcel/11162

Das Netz ist politisch · Nicht wirklich «Responsible Disclosure»: Die Extraportion Spam über die Festtage - Das Netz ist politischWenige Tage bevor alle Systemadministratoren sich zu ihren Familien in die verdienten Weihnachtsferien zurückziehen, lässt SEC Consult die Bombe platzen: Die

In 24h + 40 minutes, the #SMTPSmuggling presentation by Timo Longin from SEC consult will start at #37C3. Maybe someone in the audience can ask about the weird shenanigans of not informing open source projects like postfix, exim, sendmail directly back in June and instead causing frantic hard work for them during Christmas. fahrplan.events.ccc.de/congres

fahrplan.events.ccc.deLecture: SMTP Smuggling – Spoofing E-Mails Worldwide | Wednesday | Schedule 37th Chaos Communication Congress
Continued thread

After having been informed by @mathieui that #Exim is also affected, I compiled a list of what #SECConsult documented and what has been found out in the meantime. SEC Consult documented 11 mail systems (software and/or providers; many with millions of accounts) vulnerable to some form of #SMTPSmuggling. But they only informed 3. With #Exim also vulnerable (apparently presumed "clean" by SEC Consult), the list is now 12.
netfuture.ch/2023/12/smtp-smug

Netfuture: The future is networked · SMTP Smuggling Status«SMTP Smuggling» is a vulnerability that allows to circumvent some mail checks at the receiver and therefore will allow additional spam and/or phishing messages through. Here is the list of what we currently know. Interested in the full story? I have written a German 🇩🇪 article on SMTP Smuggl