The critical role played by email has led to a range of extension protocols (e.g., SPF, DKIM, DMARC) designed to protect against the spoofing of email sender domains. These protocols are complex as is, but are further complicated by automated email forwarding -- used by individual users to manage multiple accounts and by mailing lists to redistribute messages. In this paper, we explore how such email forwarding and its implementations can break the implicit assumptions in widely deployed anti-spoofing protocols. Using large-scale empirical measurements of 20 email forwarding services (16 leading email providers and four popular mailing list services), we identify a range of security issues rooted in forwarding behavior and show how they can be combined to reliably evade existing anti-spoofing controls. We further show how these issues allow attackers to not only deliver spoofed email messages to prominent email providers (e.g., Gmail, Microsoft Outlook, and Zoho), but also reliably spoof email on behalf of tens of thousands of popular domains including sensitive domains used by organizations in government (e.g., state.gov), finance (e.g., transunion.com), law (e.g., perkinscoie.com) and news (e.g., washingtonpost.com) among others.
翻译:摘要:电子邮件扮演的关键角色催生了一系列扩展协议(例如SPF、DKIM、DMARC),旨在防范对电子邮件发送域名的欺骗。这些协议本身已相当复杂,而自动电子邮件转发——被个人用户用以管理多个账户,或被邮件列表用以重新分发消息——进一步加剧了这种复杂性。本文探讨了此类电子邮件转发及其实现如何破坏广泛部署的反欺骗协议中的隐含假设。通过对20个电子邮件转发服务(包括16家主流电子邮件提供商和四个流行的邮件列表服务)的大规模实证测量,我们识别了一系列根植于转发行为的安全问题,并展示了这些问题如何被组合利用,以可靠地规避现有的反欺骗控制。我们进一步展示了这些问题如何使攻击者不仅能够向知名电子邮件提供商(如Gmail、Microsoft Outlook和Zoho)投递欺骗性电子邮件,还能可靠地以数万个流行域名的名义进行欺骗,这些域名包括政府机构(如state.gov)、金融领域(如transunion.com)、法律领域(如perkinscoie.com)以及新闻媒体(如washingtonpost.com)等敏感域名。