[31789] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Privacy leak in VeriSign's SiteFinder service #2

daemon@ATHENA.MIT.EDU (Henning Rust)
Thu Sep 25 13:14:04 2003

Date: Thu, 25 Sep 2003 11:37:54 +0200 (MEST)
From: Henning Rust <Henning.Rust@stud.uni-hannover.de>
To: Marco Ivaldi <raptor@0xdeadbeef.info>
Cc: "BUGTRAQ@SECURITYFOCUS. COM" <BUGTRAQ@securityfocus.com>
In-Reply-To: <Pine.BSO.4.58.0309242048360.24545@anarch0.rewt.mil>
Message-ID: <Pine.GSO.4.58.0309251136210.8359@studserv.stud.uni-hannover.de>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII


On Wed, 24 Sep 2003, Marco Ivaldi wrote:

> What if Verisign is planning to open more similar TCP/IP services on that
> host? What if they're going to further modify the existing ones, to better
> invade individuals' privacy?

Up to now, e-mails addressed to misspelled mail domains will not be sent
to Verisign's Fake-SMTP-service as MX records are used for mail-domain
resolving. Verisign did not set up wildcard MX records.

However, if you configure your E-Mail-Program or local
Mail-Transfer-Agent and misspell the hostname of the SMTP-Server for
outgoing mail, all outgoing mail will be sent to their Fake-SMTP service.

What if Versign is planning to add wildcard MX records as well, so that
any mail addressed to mistyped/non-existant mail domains like
"foobar@sdfsgggdfasfasdf.com" will be sent to their fake SMTP service?

Expect the worst!

hepp...
        Henning

--

home help back first fref pref prev next nref lref last post