You should have wrote to the ceo from their own domain
@easternplatypus Жыл бұрын
that would've been funny but probably not worth risking criminal charges 😭
@LinkageAX Жыл бұрын
Is it really criminal if the CEO says it's a feature of the product? It's being used as intended at that point imo
@alexc7095 Жыл бұрын
lol... just lol waw..... I can see it now scam as a service on darkweb 😂😂😂😂😂
@MasterThief117 Жыл бұрын
@@easternplatypus The CEO themselves said it was a feature of the service and if domains didn't like it, they could secure themselves via DMARC/DKIM. The CEO essentially gave free reign to spoof their own domain using the service.
@MrTweetyhack3 ай бұрын
@@easternplatypus only if they catch you
@claudiusraphael9423 Жыл бұрын
Endless stream of Bruh-moments from minute 9 on .. Nicely done!
@eyezikandexploits3 ай бұрын
Sending himself a email from blackhat is top notch irony
@eternalillusion Жыл бұрын
Love this mofo. Splendid and efficient, zero-hopium talk. 10/10.
@devonrogers129921 күн бұрын
Bro😢
@criticaloptimist Жыл бұрын
I’m both shocked this vulnerability is a thing but also not surprised so many companies don’t have SPF/DKIM set up. Email is a mess to secure, super complicated, and I don’t think most companies really have an expert managing their domains. But I do know that any company that would find out about this vulnerability would never be ok with this.
@YuanLiuTheDoc Жыл бұрын
I can believe that your E-mail to the CEO went to spam folder - because he marked you as nuisance after your second "offense". But I cannot believe that a CEO who was perhaps not very tech savvy didn't pass your concern about the Cloudflare API might change the calculus to CTO.
@Shpongle64 Жыл бұрын
Well now the world knows about cloud flare
@thefloorhasgone Жыл бұрын
Great talk. I found his manner of speaking quite relaxing to listen to 😊
@juliacaesar8462 Жыл бұрын
This guy is a great speaker. So comfortable and fun to listen to. Very informative and I enjoyed the humor. Well done!!
@TheCocoaDaddy Жыл бұрын
Awesome video. I have experience with SPF, DKIM and DMARC but have never looked into the ARC headers. Thanks for the thorough explanation!
@Leetfin Жыл бұрын
Patched after this talk lol
@fiendlybrds Жыл бұрын
Nice I am loving this defcon dump!
@theycallme_nightmaster Жыл бұрын
35:36 I can tell you that this is indeed possible using certain security gateways.
@rhysperry111 Жыл бұрын
Still can't believe DKIM isn't widely setup and that most mail providers ignore it if SPF passes
@geroffmilan3328 Жыл бұрын
This
@Tetsuo6995 Жыл бұрын
What I truly don't understand is why DMARC passes if SPF "OR" DKIM is passed. So with an AND you would verify that : 1. The correct IP sent you the email (SPF) 2. The correct server signed the mail and that its headers are not tampered with DKIM But no, you can just set it to an OR. But on the other hand, some providers trust ARC as some kind of guarantee that an email is what it pretends to be. Email security is shite. I kind of hope we will one day drop SMTP alltogether and move on to completely different tech.
@geroffmilan3328 Жыл бұрын
@@Tetsuo6995 it's fkn dumb💯 I need to re-check what the RFCs say here, but agree 100% about email security. This is what we get when we continue bolting shit onto a protocol from the 1970s whilst shackling ourselves to backwards compatibility. On the other hand, as a pen tester "by design" flaws are the gift that keeps on giving. The only thing which will move the needle on this, sadly, will be an attack which is a) trivial to implement and b) has staggering adverse *financial* impact. Add this to the already-huge pile of "why market forces don't solve everything".
@thewhitefalcon8539 Жыл бұрын
DKIM is hard to get right. SPF is easy.
@geroffmilan3328 Жыл бұрын
@@thewhitefalcon8539 I find it's the reverse, but it does vary by mail service/platform. With DKIM you're just creating a keypair, ensuring the mail service uses it when sending, and publishing the DNS record for it. With SPF, you have to ensure there are no more than 10 entries or it becomes useless - so it's a good to a) never use a mail service that can't handle DKIM and b) always use DKIM rather than SPF to authorise third-party mail services to use the domain
@RandornCanis Жыл бұрын
You can sometimes enforce DKIM alignment inside DMARC by setting your SPF record to -all. This isn't so uncommon because forwards and mailing lists break SPF anyways. You'll just need another SPF domain for the envelope from header, but this intentionally leaves only DKIM for domain alignment.
@drstefankrank Жыл бұрын
The only problem is receivers who don't support DKIM an solely rely on SPF, but I consider this their problem.
@YuanLiuTheDoc Жыл бұрын
(Mail) security is everybody's problem. Breach of a recipient can negatively impact the sender, not to say a million other entities that the breached party has connections with.
@idiotwidowmaker8932 Жыл бұрын
Soooo it would be hypothetically very interesting if some people delivered to the CEOs mailbox AI generated invoices, “escalations” , etc just things that cant be ignored and see how fast it gets fixed
@erbterb2 ай бұрын
What if it is feature and not a bug? Spam some command and control malware, get click on link, get control of target phone, download "ai" software, harvest all the data. Bring out gallons of hand lotion amd let er rip.
@rpm10k. Жыл бұрын
This is hilarious and fantastic. Great speaker.
@adrianantoci118711 ай бұрын
That is just incredible. Amazing talk.
@magnusthorne Жыл бұрын
Wow. What a great talk. Great job.
@drstefankrank Жыл бұрын
It would have been so easy, even with their relay in SPF. Do the same like Microsoft or Google does. Do API authentication and tie this authentication to a verified list of domain you own. They all need you to authenticate your domain at initial setup with a unique txt record in dns for example.
@louis-lau Жыл бұрын
They really should have done that, but I can also understand the perspective. Since their target market is hosts that don't control the domains and probably use standard control panels like cpanel or directadmin, there's no way to verify the domains with mailchannels out of the box in those panels. Now their customers need to do some kind of custom integration instead of just using them as an SMTP relay with any off the shelf setup they want. Before these authentication protocols email had been spoofable for decades, and for many organizations today it still is. For them, it's simply a tradeoff between ease of customer acquisition, and protection against spoofing between customers. So while I agree with you, I can understand why this wasn't done. Email is insecure in a variety of ways. Hopefully one day we'll get to the point that it's not.
@hangingwithvoid360 Жыл бұрын
His demo vid didn't play because its synced to online only XD its not stored on his PC. lmaooo The cloud strikes again.
@Its-Just-Zip Жыл бұрын
If I remember correctly, there was a talk recently about fixing Dmarc to where dmarc would fail if either dkim or SPF failed. What's going on with that stuff? I believe some email providers will throw an error if either DKIM or SPF fail but that really needs to become like a standard and they need to start throwing that error if DKIM is not set up because there is really no reason not to be running all of the above.
@jfbeam Жыл бұрын
MC's CEO is technically correct... SPF assumes one domain = one IP = one domain. That's not necessarily true. And it's never true on any email aggregation site like MC. Their API needs to authenticate who is attempting to send the message, then they can police what domains are used. The way they've integrated with CF eliminates all that - they just look for it to come from any CF IP, without CF disclosing anything about the CF user / account. (this would be rather simple for both of them to fix.)
@randomblogger2835 Жыл бұрын
At SMTP2GO we had a simmilar issue authenticating email sourced from Salesforce, but fortunately they exposed their customer id in an email header so we used that in combination the the source IP address, Salesforce now support full SASL SMTP authentication.
@MrTweetyhack3 ай бұрын
your emails were allegedly going to spam yet somehow he was responded to you earlier emails. I bet this company is just some old guy in his basement.
@MrMilarepa108 Жыл бұрын
Can't follow but he's got it, I'd trust him with my email server 10 days out of 10.
@MrMilarepa108 Жыл бұрын
Additional note: I do not have an email server. But if I had, I know who I wanted to be in charge of it.😊
@louis-lau Жыл бұрын
@@MrMilarepa108 To be completely fair, if whoever is hosting your email isn't aware of this issue, they're not that competent or specialized. I found myself nodding along with almost the whole talk, none of it was really news to me. Email is layers upon layers of stuff, all meant to be backwards compatible. Mailchannels should just really have their customers upload a list of domains they intend to send from, but they're far from the only one that this issue applies to. Email just isn't great for secure messaging in many ways, maybe we'll get there one day :)
@Spooky_OG Жыл бұрын
Thanks for the knowledge. Very cool.
@Pervy Жыл бұрын
Hey it's byt3bl33d3r. I've been checking out this blog posts for years lol.
@stonelox Жыл бұрын
They must be in on the email spam profit scheme
@robmorgan1214 Жыл бұрын
Welp... time to block all cloudflare addresses.
@CreedFlintАй бұрын
23:22 , talking about unable to use DKIM when ARC goes through other marketing servers for 'sginatures' of email. Does that then mean the only line of defense is SPF, considering spf OR dkim only need to be authenticated for an email to pass through to an inbox?
@qmurec Жыл бұрын
awesome talk!
@NeverGiveUpYo Жыл бұрын
Epic talk
@n.lightnin8298 Жыл бұрын
“A heroin convention” 🤔 😂
@realdavidpain23 күн бұрын
There probably even is a target audience for heroin and security related talks 🧐
@comosaycomosah Жыл бұрын
Lmao thats awesome spoofed his entry
@comediavietii1245 Жыл бұрын
this is dangerous
@aciid_03 ай бұрын
how tf did blackhat not even use SPF/DKIM until 2023? am I missing something? that shit is the first thing I set up on any new email server
@carlmelgaard5423 Жыл бұрын
Awesome stuff!
@SadeN_0 Жыл бұрын
Just... wow.
@qu3nt Жыл бұрын
oh look it’s 1996 again
@Stoney_Eagle Жыл бұрын
I guess this is why I can no longer escape the spam 😑
@frango_e_salada Жыл бұрын
PARABÉNS POR CALAR A BOCA DAQUELE VELHO FACISTA!!!
@MatthiewMarks Жыл бұрын
31:46 This is why I hate using cloud storage
@skyracer-mk8hg Жыл бұрын
Didnt they add domain lockdown or whatever it is called for fix that? EDIT: Just got to 34:00 and well yea..
@byt3bl33d3r Жыл бұрын
You can still just sign up via their website and spoof all domains via their normal SMTP relay. The domain lockdown record addressed a symptom not the root cause (lack of sender identity verification)
@Tahsn31 Жыл бұрын
I am the first person who is watching this. Feel like special hahaha
@claudiusraphael9423 Жыл бұрын
You are the One.
@feuerherz007 Жыл бұрын
the chosen one 😢
@SnapWireOnlyOne Жыл бұрын
LMAO i was doing this before 2012 i was just bombing company's email accounts for a laugh
@Adamizion Жыл бұрын
Does it work anymore?
@realdavidpain23 күн бұрын
Just hop on the Cloudflare train 😏
@fun-uj6be6 ай бұрын
If it's not a spam it's a ham.
@alexasouza4152 Жыл бұрын
Spoofing blackhat in a defcon talk, awesome! LMAO HAHA
@tripletsborn Жыл бұрын
Impersonating brainpop lol
@gautamkrishnar28 күн бұрын
Bruh!
@ettyxcbyrcburcbtxcfhcdtyurt18 күн бұрын
HAHAHAHAHAHAHAHAHAHHAHAHAHAHHAHAHAHAHAHHAHAHAHAHAHAH yeah so im moving countries. this has been happening to me for 3 years, and my chest cannot stomach anyone from my past life confronting me about receiving mail from me. i know some doctors that broke even in their 40s and ended their 50s by retiring comfy. im done with machines.
@Michael_Jackson187 Жыл бұрын
You get domain lockdown when you try this, has anyone done this or is everyone just watching lol
@dussedagod Жыл бұрын
domain lockdown?
@Michael_Jackson187 Жыл бұрын
@@dussedagod yea i spent like 30min to an hour setting everything up, went to use some of the domains provided in that list and they are all locked down lol.
@quadrupledamage Жыл бұрын
@@dussedagod He talked about it at the end, Cloudflare added Domain Lockdown to make sure other Cloudflare Worker users can't send emails from your domain. From what I understand, this issue still affects MailChannel, and with $80 you can spoof every single MC user.
@deancrypto5939 Жыл бұрын
patched ??
@thegu5 Жыл бұрын
yupp
@deancrypto5939 Жыл бұрын
actually NO@@thegu5 just deploy your own worker and use a different domain ill drop some updated code later to make it 10 times easier
@muhammadgoran4898 Жыл бұрын
i think they patched it cuz i tried my domain which hasnt any email record and it didnt work@@deancrypto5939
@rpm10k. Жыл бұрын
He won't
@KingKongBlanue Жыл бұрын
@@deancrypto5939Where’s the updated code sir ?
@connoradair Жыл бұрын
Straight jokes
@Crypto_Chief Жыл бұрын
😂😂😂. This hilarious
@-Ncrypt Жыл бұрын
Bet you he’s got a job by now 😂
@ChairmanHehe Жыл бұрын
cloudflare so fuckin sussy
@svettnabb Жыл бұрын
Arc=pass working must be because of lazy and greedy regex.
@erbterb2 ай бұрын
Look it is the Crowdmail guy. All lazy programmers using the same code with a centralised service structure. No vulns here.
@Michael_Jackson187 Жыл бұрын
You need an api key
@stubstunner Жыл бұрын
What if you host your own MX record for a non-existent domain? I bet it works.
@mini_bomba Жыл бұрын
you can't put a DNS record on a DNS domain that doesn't exist...
@geroffmilan3328 Жыл бұрын
@@mini_bomba 💯 - or one you don't own/have zone file access
@Tetsuo6995 Жыл бұрын
@@mini_bomba Nothing prevents you from putting anything in your public DNS server. It's simply that nobody will contact your server for these records since the associated domain is not registered anywhere. At least that's my understanding. I say that because I think you can prepare in advance some records for a domain you are about to obtain. And when you become the Authority for this domain, your MX, SPF records will start to get hits.
@gamer-gw9iy Жыл бұрын
7:37
@superhanspaul Жыл бұрын
"null" is german and means "zero" "0"
@realdavidpain23 күн бұрын
🤨
@jbs. Жыл бұрын
Closed when I heard 'allowlist'
@skyemegakitty Жыл бұрын
you won't be missed o/ bye
@Michael_Jackson187 Жыл бұрын
Where can you point me? I tried this and you get domain lockdown if you try to use any of these domains
@jackda216811 ай бұрын
@@Michael_Jackson187 hey did you find any solution ??? or do you pay 80$ for spoofing other domains ?
@bradmca20222 ай бұрын
Less than like 5 like minutes in and like i just like can't take the like 100000 unnecessary like uses of the like word like anymore like