home.social

#timolongin — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #timolongin, aggregated by home.social.

fetched live
  1. Timo Longin @login introduces SMTP smuggling, a novel technique to spoof fully SPF-validated emails from various popular domains including @microsoft.com.

    Wow. It's incredible nobody found this before. It's the first of its kind. Probably not the last...!

    youtu.be/V8KPV96g1To

    Related:
    media.ccc.de/v/37c3-11782-smtp
    postfix.org/smtp-smuggling.html
    malwarebytes.com/blog/news/202

  2. SPF-valid spoofed mail from [email protected] 😈 ?

    Timo Longin @login stumbled upon SMTP Smuggling while looking for vulnerabilities in the Simple Mail Transfer Protocol.

    Great work and great talk!

    #Smtp #SmtpSmuggling #TimoLongin #37c3

    media.ccc.de/v/37c3-11782-smtp

  3. Okay, now I'm a bit sad that I won't be at #37C3, and it's because of this talk:
    events.ccc.de/congress/2023/hu

    Presenter #TimoLongin found an exploit in SMTP, notified commercial vendors GMX, Microsoft & Cisco in July, then published a blog post in the week before Christmas that describes how the attack works. Free software maintainers and admins were not warned in advance and had to rush to build workarounds.

    Would've loved to talk to him about his idea of "responsible disclosure".

    #SMTPSmuggling