Email hacking via the SMTP protocol
We rely on emails being transmitted securely. Various service providers are responsible for this, depending on the route our emails take from sender to recipient...
We rely on emails being transmitted securely. Various service providers are responsible for this, depending on the route our emails take from sender to recipient.
With incoming emails, we check the sender, and we rely on the other side also identifying us by the sender. But what if you could freely choose the sender of the emails you send to someone?
https://youtu.be/rMk_aGlmzPk
Hackers can do exactly that if mail servers are simply "run" but not secured. In this video I show how it works.
The SMTP protocol – Simple Mail Transfer Protocol
It was one of the first protocols agreed on with the emergence of the internet as we know it today. It was created as early as 1982.
When it was created, security was NOT a top priority. All the more astonishing that the whole world has now been exchanging emails with this very insecure protocol for almost 40 years.
Over the years there have been numerous extensions and additions that make secure communication possible. However, these have to be assessed, used and activated individually. For private individuals, that is the responsibility of each person or of the email service provider they use.
▶ Watch video: Mailversand-Ablauf2 (MP4)
In companies, this work is done by the IT department, by configuring the mail servers or end devices. Unfortunately, especially in small and medium-sized companies, important security measures are often not taken because they are not part of the original protocol.
But various hosting providers also have a range of problems configuring mail servers securely because of the complexity involved.
But how can you protect yourself as a user? How can you check whether your own systems are vulnerable to this kind of manipulation ...
I want to do my part. With my tests and training, I help you secure your company's communication.