PRESS-NEWS.org - Press Release Distribution
PRESS RELEASES DISTRIBUTION

Scammers can abuse security flaws in email forwarding to impersonate high-profile domains

Some of the domains vulnerable include Mastercard, The Washington Post and the Department of State

Scammers can abuse security flaws in email forwarding to impersonate high-profile domains
2023-09-05
(Press-News.org) Sending an email with a forged address is easier than previously thought, due to flaws in the process that allows email forwarding, according to a research team led by computer scientists at the University of California San Diego. 

The issues researchers uncovered have a broad impact, affecting the integrity of email sent from tens of thousands of domains, including those representing organizations in the U.S. government–such as the majority of U.S. cabinet email domains, including state.gov, as well as security agencies. Key financial service companies, such as Mastercard, and major news organizations, such as The Washington Post and the Associated Press, are also vulnerable. 

It's called forwarding-based spoofing and researchers found that they can send email messages impersonating these organizations, bypassing the safeguards deployed by email providers such as Gmail and Outlook. Once recipients get the spoofed email, they are more likely to open attachments that deploy malware, or to click on links that install spyware on their machine.

Such spoofing is made possible by a number of vulnerabilities centered on forwarding emails, the research team found. The original protocol used to check the authenticity of an email implicitly assumes that each organization operates its own mailing infrastructure, with specific IP addresses not used by other domains. But today, many organizations outsource their email infrastructure to Gmail and Outlook. As a result, thousands of domains have delegated the right to send email on their behalf to the same third party. While these third-party providers validate that their users only send email on behalf of domains that they operate, this protection can be bypassed by email forwarding. 

For example, state.gov, the email domain for the Department of State, allows Outlook to send emails on their behalf. This means emails claiming to be from state.gov would be considered legitimate if they came from Outlook’s email servers. As a result, an attacker can create a spoofed email–an email with a fake identity–pretending, for example, to come from the Department of State--and then forward it through their personal Outlook account. Once they do this, the spoofed email will now be treated as legitimate by the recipient, as it is coming from an Outlook email server.

Versions of this flaw also exist for five other email providers, including iCloud. The researchers also discovered other smaller issues that impact users of Gmail and Zohomail– a popular email provider in India. 

Researchers reported the issue to Microsoft, Apple and Google but to their knowledge, it has not been fully fixed. 

“That is not surprising since doing so would require a major effort, including dismantling and repairing four decades worth of legacy systems,” said Alex Liu, the paper’s first author and a Ph.D. student in the Jacobs School Department of Computer Science and Engineering at UC San Diego. “While there are certain short-term mitigations that will significantly reduce the exposure to the attacks we have described here, ultimately email needs to stand on a more solid security footing if it is to effectively resist spoofing attacks going forward.” 

The team presented their findings at the 8th IEEE European Symposium on Privacy and Security, July 3 to 7, 2023, in Delft, where the work won best paper.  

Different attacks

Researchers developed four different types of attacks using forwarding. 

For the first three, they assumed that an adversary controls both the accounts that send and forward emails. The attacker also needs to have a server capable of sending spoofed email messages and an account with a third party provider that allows open forwarding. 

The attacker starts by creating a personal account for forwarding and then adds the spoofed address to the accounts’s white list–a list of domains that won’t be blocked even if they don’t meet security standards. The attacker configures their account to forward all email to the desired target. The attacker then forges an email to look like it originated from state.gov and sends the email to their personal Outlook account. Then all the attacker has to do is forward the spoofed email to their target. 

More than 12 percent of the Alexa 100K most popular email domains–the most popular domains on the Internet– are vulnerable to this attack. These include a large number of news organizations, such as the Washington Post, the Los Angeles Times and the Associated Press, as well as domain registrars like GoDaddy, financial services, such as Mastercard and Docusign and large law firms. In addition, 32% of .gov domains are vulnerable, including the majority of US cabinet agencies, a range of security agencies, and agencies working in the public health domain, such as CDC. At the state and local level, virtually all primary state government domains are vulnerable and more than 40% of all .gov domains are used by cities. 

In a second version of this attack, an attacker creates a personal Outlook account to forward spoofed email messages to Gmail. In this scenario, the attacker takes on the identity of a domain that is also served by Outlook, then sends the spoofed message from their own malicious server to their personal Outlook account, which in turn forwards it to a series of Gmail accounts. 

Roughly 1.9 billion users worldwide are vulnerable to this attack. 

Researchers also found variations of this attack that work for four popular mailing list services: Google groups, mailman, listserv and Gaggle.

Potential solutions

Researchers disclosed all vulnerabilities and attacks to providers. Zoho patched their issue and awarded the team a bug bounty. Microsoft also awarded a bug bounty and confirmed the vulnerabilities. Mailing list service Gaggle said it would change protocols to resolve the issue. Gmail also fixed the issues the team reported and iCloud is investigating. 

But to truly get to the root of the issue, researchers recommend disabling open forwarding, a process that allows users to configure their account to forward messages to any designated email address without any verification by the destination address. This process is in place for Gmail and Outlook. In addition, providers such as Gmail and Outlook implicity trust high-profile email services, delivering messages forwarded by these emails regardless. 

Providers should also do away with the assumption that emails coming from another major provider are legitimate, a process called relaxed validation policies.

In addition, researchers recommend that mailing lists request confirmation from the true sender address before delivering email. 

“A more fundamental approach would be to standardize various aspects of forwarding,” the researchers write. “However, making such changes would require system-wide cooperation and will likely encounter many operational issues.” 

Methods 

For each service, researchers created multiple test accounts and used them to forward email to recipient accounts they controlled. They then analyzed the resulting email headers to better understand which forwarding protocol the service used. They tested their attacks on 14 email providers, which are used by 46% of the most popular internet domains and government domains. 

They also created mailing lists under existing services provided by UC San Diego, and by mailing list service Gaggle. 

Researchers only sent spoofed email messages to accounts they created themselves. They first tested each attack by spoofing domains they created and controlled. Once they verified that the attacks worked, they ran a small set of experiments that spoofed emails from real domains. Still, the spoofed emails were only sent to test accounts the researchers created. 

“One fundamental issue is that email security protocols are distributed, optional and independently configured components,” the researchers write. This creates a large and complex attack surface with many possible interactions that cannot be easily anticipated or administrated by any single party. “

Forward Pass: On the Security Implications of Email Forwarding Mechanism and Policy

Alex Enze Liu, Ariana Mirian, Grant Ho, Geoffrey M. Voelker and Stefan Savage, UC San Diego Department of Computer Science and Engineering

Gautam Akiwate, Stanford University

Mattijs Jonker, University of Twente, Netherlands


 

 






 

END

[Attachments] See images for this press release:
Scammers can abuse security flaws in email forwarding to impersonate high-profile domains Scammers can abuse security flaws in email forwarding to impersonate high-profile domains 2 Scammers can abuse security flaws in email forwarding to impersonate high-profile domains 3

ELSE PRESS RELEASES FROM THIS DATE:

Experts propose new global definition of acute respiratory distress syndrome

2023-09-05
Sept. 5, 2023 – In a new report posted online in the  American Journal of Respiratory and Critical Care Medicine, a global consensus conference of 32 critical care experts with broad international representation and from diverse backgrounds has proposed a new definition of acute respiratory distress syndrome (ARDS). In addition to the experts, critical care societies from around the world provided input,  once they received feedback from their members. The report, which builds on the 2012 Berlin Definition of ARDS, will be published Jan. 1, 2024 in the American Thoracic Society’s AJRCCM. ARDS is a life-threatening illness in which the lungs ...

Crowdsourcing contests: Understanding what brings high rewards, low risk

Crowdsourcing contests: Understanding what brings high rewards, low risk
2023-09-05
AMES, IA – During Frito-Lay's first "Crash the Super Bowl" contest in 2006, thousands of participants submitted 30-second videos promoting Doritos. Entries were winnowed down to five finalists, and a public vote selected the winning commercial, which aired during the most watched American television broadcast of the year. The ad boosted Doritos sales and pulled in awards, sparking other big brands, like Nestlé, BMW and Fisher-Price, to launch their own crowdsourcing contests. "Crowdsourcing has become more prevalent over the last decade. It can generate innovative ideas and solutions and engage ...

Obesity experts spotlight safety gap in clinical trials and drug labeling for people with obesity

2023-09-05
A new opinion piece published in Health Affairs Forefront raises questions around current approaches to assess drug safety and effectiveness in people with obesity. The article sheds light on how increased body fat can modify the effects of drugs used to treat common conditions, in some cases rendering the drugs ineffective or unsafe for people with obesity. The article, titled “Assessments Of Drug Safety And Effectiveness Continue To Fail People With Obesity,” argues that drug manufacturers should be required to show correct dosing instructions on their labels ...

Florida Museum researcher advances to finals in multimillion-dollar biodiversity competition

Florida Museum researcher advances to finals in multimillion-dollar biodiversity competition
2023-09-05
Over the course of four weeks this summer, a motley crew of biologists, engineers, entrepreneurs and programmers gathered at predetermined sites within Windsor Nature Park, a 185-acre tropical rainforest located in the heart of Singapore. They’d traveled from all over the world to participate in a one-of-a-kind competition hosted by the XPRIZE Foundation, in which 13 teams would have three days to identify as many organisms within the forest as possible. Up to 10 winning teams would equally split $2 million and advance to the 2024 finals, where they’d vie for the first-place prize of $5 million. But there was a catch: All observations and data collection ...

The first book to combine mineral nutrition and plant disease gets updated

The first book to combine mineral nutrition and plant disease gets updated
2023-09-05
Approximately 95% of the world’s food supply is directly or indirectly produced on soil, according to the Food and Agriculture Organization of the United Nations. Soil health is therefore critical to the health of all living organisms—especially plants. Equally as critical, resources that consider the overlap between soil’s mineral nutrition and plant diseases have been scarce, until members of the American Phytopathological Society (APS) recognized this gap. APS PRESS has newly published an updated edition of the first book to successfully combine the two important plant science disciplines of nutrition and pathology. Mineral Nutrition and Plant Disease, ...

IKIDS child health research gets another boost in funding

IKIDS child health research gets another boost in funding
2023-09-05
CHAMPAIGN, Ill. — Seven years after an initial $17.9 million award from the National Institutes of Health, the Illinois Kids Development Study at the University of Illinois Urbana-Champaign will receive approximately $13.7 million – awarded in two phases – to continue its work for another seven years. The money coming to Illinois is part of a national collaborative effort to explore how environmental exposures influence child development, cognition, growth and health. IKIDS is part of Environmental Influences on Child Health Outcomes, a national initiative to study five ...

Does a “surprise” factor in gift-giving affect beneficiaries’ gratitude? Scientists answer

Does a “surprise” factor in gift-giving affect beneficiaries’ gratitude? Scientists answer
2023-09-05
Gratitude is a strong emotion, usually felt by a person who benefits from an intentional good deed of another person. Receiving gifts or benefits can instill a feeling of gratitude in people who receive them, i.e., beneficiaries, encouraging them to be more prosocial, while also helping to create a bond with their benefactors. This has led several researchers to examine the determinants of gratitude. Interestingly, beneficiaries often have preconceived beliefs about receiving a benefit. For instance, they may have no prior expectations of receiving a ...

Clarissa Campbell and Barbara Maier at CeMM receive ERC Starting Grants

Clarissa Campbell and  Barbara Maier at CeMM  receive ERC Starting Grants
2023-09-05
Two scientists at the CeMM Research Center for Molecular Medicine of the Austrian Academy of Sciences have received prestigious ERC Starting Grants from the European Commission: Clarissa Campbell and Barbara Maier. In Clarissa Campbell's laboratory, researchers are working to better understand the interplay between the immune system and metabolism. Barbara Maier and her team are researching the role of lymph nodes in the context of cancer. (Vienna, 5 September 2023) The ERC grants are among the most prestigious and competitive research grants offered ...

Faster postal service linked to better voter turnout

2023-09-05
PULLMAN, Wash. – A more efficient U.S. Postal Service can increase voter turnout in all states regardless of their mail voting laws, according to a Washington State University study. WSU researcher Michael Ritter analyzed election data from 2012 through 2020, when the pandemic encouraged many more people than usual to vote by mail. He found that in general more accessible mail voting laws, such as universal mail-in voting and no-excuse mail voting, increased the probability that individuals would vote. Restrictive laws, such as requiring ...

Scientists synthesize new organometallic “sandwich” compound capable of holding more electrons

Scientists synthesize new organometallic “sandwich” compound capable of holding more electrons
2023-09-05
Organometallic compounds, molecules made up of metal atoms and organic molecules, are often used to accelerate chemical reactions and have played a significant role in advancing the field of chemistry.  Metallocenes, a type of organometallic compound, are known for their versatility and special "sandwich" structure. Their discovery was a significant contribution to the field of organometallic chemistry and led to the awarding of the Nobel Prize in Chemistry in 1973 to the scientists who discovered and explained their sandwich structure.  The ...

LAST 30 PRESS RELEASES:

Study shows psychedelic drug psilocybin gives comparable long-term antidepressant effects to standard antidepressants, but may offer additional benefits

Study finds symptoms of depression during pregnancy linked to specific brain activity: scientists hope to develop test for “baby blues” risk

Sexual health symptoms may correlate with poor adherence to adjuvant endocrine therapy in Black women with breast cancer

Black patients with triple-negative breast cancer may be less likely to receive immunotherapy than white patients

Affordable care act may increase access to colon cancer care for underserved groups

UK study shows there is less stigma against LGBTQ people than you might think, but people with mental health problems continue to experience higher levels of stigma

Bringing lost proteins back home

Better than blood tests? Nanoparticle potential found for assessing kidneys

Texas A&M and partner USAging awarded 2024 Immunization Neighborhood Champion Award

UTEP establishes collaboration with DoD, NSA to help enhance U.S. semiconductor workforce

Study finds family members are most common perpetrators of infant and child homicides in the U.S.

Researchers secure funds to create a digital mental health tool for Spanish-speaking Latino families

UAB startup Endomimetics receives $2.8 million Small Business Innovation Research grant

Scientists turn to human skeletons to explore origins of horseback riding

UCF receives prestigious Keck Foundation Award to advance spintronics technology

Cleveland Clinic study shows bariatric surgery outperforms GLP-1 diabetes drugs for kidney protection

Study reveals large ocean heat storage efficiency during the last deglaciation

Fever drives enhanced activity, mitochondrial damage in immune cells

A two-dose schedule could make HIV vaccines more effective

Wastewater monitoring can detect foodborne illness, researchers find

Kowalski, Salonvaara receive ASHRAE Distinguished Service Awards

SkAI launched to further explore universe

SLU researchers identify sex-based differences in immune responses against tumors

Evolved in the lab, found in nature: uncovering hidden pH sensing abilities

Unlocking the potential of patient-derived organoids for personalized sarcoma treatment

New drug molecule could lead to new treatments for Parkinson’s disease in younger patients

Deforestation in the Amazon is driven more by domestic demand than by the export market

Demand-side actions could help construction sector deliver on net-zero targets

Research team discovers molecular mechanism for a bacterial infection

What role does a tailwind play in cycling’s ‘Everesting’?

[Press-News.org] Scammers can abuse security flaws in email forwarding to impersonate high-profile domains
Some of the domains vulnerable include Mastercard, The Washington Post and the Department of State