Learn Excel and Financial Modeling the Way Finance Teams Actually Use Them
Learn Backend Development Part-Time, Online
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk examines how attackers bypass SPF, DKIM, and DMARC by exploiting inconsistencies among email servers, authentication components, and mail user agents. It presents attacks tested against major email services and clients, including forged messages bearing legitimate DKIM signatures.
Syllabus
Intro
How Do You Verify the Email Sender?
Background: Email Transmission
Sender Policy Framework (SPF)
Domain Message Authentication, Reporting and Conformance (MARC)
Overview of Email Authentication Flow
Key Idea of Our Attacks
Inconsistencies b/w SPF and DMARC
Inconsistencies b/w DKIM and DNS
Exp. 3a: DKIM Authentication Results Injection
a: Multiple From Headers
From Sender Ambiguity
Complex From Header Syntax
h: Exploiting Parsing Inconsistencies
Spoofing via an Email Service Account
Thinking on Defense
Taught by
Black Hat