home.social

#smtpsmuggling — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #smtpsmuggling, aggregated by home.social.

  1. It's a wrap! 🌯 Our technical guideline "BSI TR-03108 (Secure Email Transport)" is now accompanied by "BSI TR-03182 (Email Authentication)" providing guidance for email services to protect their users against impersonation attacks like Spoofing and Phishing :flan_mask:​

    bsi.bund.de/dok/tr-03182-en

    #TeamBSI #EmailAuthentication #DNSSEC #DMARC #DKIM #SPF #SMTP #SMTPSmuggling

  2. Reading about the recent SMTP and SSH vulnerabilities, I get the impression that open source projects, proprietary vendors and government agencies such as @certbund don't know how to talk to each other. They should at least have something like a red phone.

    Please comment here if you have a constructive idea on how to improve the situation! #SECconsulting seems to assume that everyone uses #VINCE, a CMU service I had never heard of.

    #SMTP:
    sec-consult.com/blog/detail/sm
    postfix.org/smtp-smuggling.htm

    #SSH:
    terrapin-attack.com/patches.ht

    #SMTPsmuggling #Terrapin #ITsec #37c3