PRESS-NEWS.org - Press Release Distribution
PRESS RELEASES DISTRIBUTION

Scammers can abuse security flaws in email forwarding to impersonate high-profile domains

Some of the domains vulnerable include Mastercard, The Washington Post and the Department of State

Scammers can abuse security flaws in email forwarding to impersonate high-profile domains
2023-09-05
(Press-News.org) Sending an email with a forged address is easier than previously thought, due to flaws in the process that allows email forwarding, according to a research team led by computer scientists at the University of California San Diego. 

The issues researchers uncovered have a broad impact, affecting the integrity of email sent from tens of thousands of domains, including those representing organizations in the U.S. government–such as the majority of U.S. cabinet email domains, including state.gov, as well as security agencies. Key financial service companies, such as Mastercard, and major news organizations, such as The Washington Post and the Associated Press, are also vulnerable. 

It's called forwarding-based spoofing and researchers found that they can send email messages impersonating these organizations, bypassing the safeguards deployed by email providers such as Gmail and Outlook. Once recipients get the spoofed email, they are more likely to open attachments that deploy malware, or to click on links that install spyware on their machine.

Such spoofing is made possible by a number of vulnerabilities centered on forwarding emails, the research team found. The original protocol used to check the authenticity of an email implicitly assumes that each organization operates its own mailing infrastructure, with specific IP addresses not used by other domains. But today, many organizations outsource their email infrastructure to Gmail and Outlook. As a result, thousands of domains have delegated the right to send email on their behalf to the same third party. While these third-party providers validate that their users only send email on behalf of domains that they operate, this protection can be bypassed by email forwarding. 

For example, state.gov, the email domain for the Department of State, allows Outlook to send emails on their behalf. This means emails claiming to be from state.gov would be considered legitimate if they came from Outlook’s email servers. As a result, an attacker can create a spoofed email–an email with a fake identity–pretending, for example, to come from the Department of State--and then forward it through their personal Outlook account. Once they do this, the spoofed email will now be treated as legitimate by the recipient, as it is coming from an Outlook email server.

Versions of this flaw also exist for five other email providers, including iCloud. The researchers also discovered other smaller issues that impact users of Gmail and Zohomail– a popular email provider in India. 

Researchers reported the issue to Microsoft, Apple and Google but to their knowledge, it has not been fully fixed. 

“That is not surprising since doing so would require a major effort, including dismantling and repairing four decades worth of legacy systems,” said Alex Liu, the paper’s first author and a Ph.D. student in the Jacobs School Department of Computer Science and Engineering at UC San Diego. “While there are certain short-term mitigations that will significantly reduce the exposure to the attacks we have described here, ultimately email needs to stand on a more solid security footing if it is to effectively resist spoofing attacks going forward.” 

The team presented their findings at the 8th IEEE European Symposium on Privacy and Security, July 3 to 7, 2023, in Delft, where the work won best paper.  

Different attacks

Researchers developed four different types of attacks using forwarding. 

For the first three, they assumed that an adversary controls both the accounts that send and forward emails. The attacker also needs to have a server capable of sending spoofed email messages and an account with a third party provider that allows open forwarding. 

The attacker starts by creating a personal account for forwarding and then adds the spoofed address to the accounts’s white list–a list of domains that won’t be blocked even if they don’t meet security standards. The attacker configures their account to forward all email to the desired target. The attacker then forges an email to look like it originated from state.gov and sends the email to their personal Outlook account. Then all the attacker has to do is forward the spoofed email to their target. 

More than 12 percent of the Alexa 100K most popular email domains–the most popular domains on the Internet– are vulnerable to this attack. These include a large number of news organizations, such as the Washington Post, the Los Angeles Times and the Associated Press, as well as domain registrars like GoDaddy, financial services, such as Mastercard and Docusign and large law firms. In addition, 32% of .gov domains are vulnerable, including the majority of US cabinet agencies, a range of security agencies, and agencies working in the public health domain, such as CDC. At the state and local level, virtually all primary state government domains are vulnerable and more than 40% of all .gov domains are used by cities. 

In a second version of this attack, an attacker creates a personal Outlook account to forward spoofed email messages to Gmail. In this scenario, the attacker takes on the identity of a domain that is also served by Outlook, then sends the spoofed message from their own malicious server to their personal Outlook account, which in turn forwards it to a series of Gmail accounts. 

Roughly 1.9 billion users worldwide are vulnerable to this attack. 

Researchers also found variations of this attack that work for four popular mailing list services: Google groups, mailman, listserv and Gaggle.

Potential solutions

Researchers disclosed all vulnerabilities and attacks to providers. Zoho patched their issue and awarded the team a bug bounty. Microsoft also awarded a bug bounty and confirmed the vulnerabilities. Mailing list service Gaggle said it would change protocols to resolve the issue. Gmail also fixed the issues the team reported and iCloud is investigating. 

But to truly get to the root of the issue, researchers recommend disabling open forwarding, a process that allows users to configure their account to forward messages to any designated email address without any verification by the destination address. This process is in place for Gmail and Outlook. In addition, providers such as Gmail and Outlook implicity trust high-profile email services, delivering messages forwarded by these emails regardless. 

Providers should also do away with the assumption that emails coming from another major provider are legitimate, a process called relaxed validation policies.

In addition, researchers recommend that mailing lists request confirmation from the true sender address before delivering email. 

“A more fundamental approach would be to standardize various aspects of forwarding,” the researchers write. “However, making such changes would require system-wide cooperation and will likely encounter many operational issues.” 

Methods 

For each service, researchers created multiple test accounts and used them to forward email to recipient accounts they controlled. They then analyzed the resulting email headers to better understand which forwarding protocol the service used. They tested their attacks on 14 email providers, which are used by 46% of the most popular internet domains and government domains. 

They also created mailing lists under existing services provided by UC San Diego, and by mailing list service Gaggle. 

Researchers only sent spoofed email messages to accounts they created themselves. They first tested each attack by spoofing domains they created and controlled. Once they verified that the attacks worked, they ran a small set of experiments that spoofed emails from real domains. Still, the spoofed emails were only sent to test accounts the researchers created. 

“One fundamental issue is that email security protocols are distributed, optional and independently configured components,” the researchers write. This creates a large and complex attack surface with many possible interactions that cannot be easily anticipated or administrated by any single party. “

Forward Pass: On the Security Implications of Email Forwarding Mechanism and Policy

Alex Enze Liu, Ariana Mirian, Grant Ho, Geoffrey M. Voelker and Stefan Savage, UC San Diego Department of Computer Science and Engineering

Gautam Akiwate, Stanford University

Mattijs Jonker, University of Twente, Netherlands


 

 






 

END

[Attachments] See images for this press release:
Scammers can abuse security flaws in email forwarding to impersonate high-profile domains Scammers can abuse security flaws in email forwarding to impersonate high-profile domains 2 Scammers can abuse security flaws in email forwarding to impersonate high-profile domains 3

ELSE PRESS RELEASES FROM THIS DATE:

Experts propose new global definition of acute respiratory distress syndrome

2023-09-05
Sept. 5, 2023 – In a new report posted online in the  American Journal of Respiratory and Critical Care Medicine, a global consensus conference of 32 critical care experts with broad international representation and from diverse backgrounds has proposed a new definition of acute respiratory distress syndrome (ARDS). In addition to the experts, critical care societies from around the world provided input,  once they received feedback from their members. The report, which builds on the 2012 Berlin Definition of ARDS, will be published Jan. 1, 2024 in the American Thoracic Society’s AJRCCM. ARDS is a life-threatening illness in which the lungs ...

Crowdsourcing contests: Understanding what brings high rewards, low risk

Crowdsourcing contests: Understanding what brings high rewards, low risk
2023-09-05
AMES, IA – During Frito-Lay's first "Crash the Super Bowl" contest in 2006, thousands of participants submitted 30-second videos promoting Doritos. Entries were winnowed down to five finalists, and a public vote selected the winning commercial, which aired during the most watched American television broadcast of the year. The ad boosted Doritos sales and pulled in awards, sparking other big brands, like Nestlé, BMW and Fisher-Price, to launch their own crowdsourcing contests. "Crowdsourcing has become more prevalent over the last decade. It can generate innovative ideas and solutions and engage ...

Obesity experts spotlight safety gap in clinical trials and drug labeling for people with obesity

2023-09-05
A new opinion piece published in Health Affairs Forefront raises questions around current approaches to assess drug safety and effectiveness in people with obesity. The article sheds light on how increased body fat can modify the effects of drugs used to treat common conditions, in some cases rendering the drugs ineffective or unsafe for people with obesity. The article, titled “Assessments Of Drug Safety And Effectiveness Continue To Fail People With Obesity,” argues that drug manufacturers should be required to show correct dosing instructions on their labels ...

Florida Museum researcher advances to finals in multimillion-dollar biodiversity competition

Florida Museum researcher advances to finals in multimillion-dollar biodiversity competition
2023-09-05
Over the course of four weeks this summer, a motley crew of biologists, engineers, entrepreneurs and programmers gathered at predetermined sites within Windsor Nature Park, a 185-acre tropical rainforest located in the heart of Singapore. They’d traveled from all over the world to participate in a one-of-a-kind competition hosted by the XPRIZE Foundation, in which 13 teams would have three days to identify as many organisms within the forest as possible. Up to 10 winning teams would equally split $2 million and advance to the 2024 finals, where they’d vie for the first-place prize of $5 million. But there was a catch: All observations and data collection ...

The first book to combine mineral nutrition and plant disease gets updated

The first book to combine mineral nutrition and plant disease gets updated
2023-09-05
Approximately 95% of the world’s food supply is directly or indirectly produced on soil, according to the Food and Agriculture Organization of the United Nations. Soil health is therefore critical to the health of all living organisms—especially plants. Equally as critical, resources that consider the overlap between soil’s mineral nutrition and plant diseases have been scarce, until members of the American Phytopathological Society (APS) recognized this gap. APS PRESS has newly published an updated edition of the first book to successfully combine the two important plant science disciplines of nutrition and pathology. Mineral Nutrition and Plant Disease, ...

IKIDS child health research gets another boost in funding

IKIDS child health research gets another boost in funding
2023-09-05
CHAMPAIGN, Ill. — Seven years after an initial $17.9 million award from the National Institutes of Health, the Illinois Kids Development Study at the University of Illinois Urbana-Champaign will receive approximately $13.7 million – awarded in two phases – to continue its work for another seven years. The money coming to Illinois is part of a national collaborative effort to explore how environmental exposures influence child development, cognition, growth and health. IKIDS is part of Environmental Influences on Child Health Outcomes, a national initiative to study five ...

Does a “surprise” factor in gift-giving affect beneficiaries’ gratitude? Scientists answer

Does a “surprise” factor in gift-giving affect beneficiaries’ gratitude? Scientists answer
2023-09-05
Gratitude is a strong emotion, usually felt by a person who benefits from an intentional good deed of another person. Receiving gifts or benefits can instill a feeling of gratitude in people who receive them, i.e., beneficiaries, encouraging them to be more prosocial, while also helping to create a bond with their benefactors. This has led several researchers to examine the determinants of gratitude. Interestingly, beneficiaries often have preconceived beliefs about receiving a benefit. For instance, they may have no prior expectations of receiving a ...

Clarissa Campbell and Barbara Maier at CeMM receive ERC Starting Grants

Clarissa Campbell and  Barbara Maier at CeMM  receive ERC Starting Grants
2023-09-05
Two scientists at the CeMM Research Center for Molecular Medicine of the Austrian Academy of Sciences have received prestigious ERC Starting Grants from the European Commission: Clarissa Campbell and Barbara Maier. In Clarissa Campbell's laboratory, researchers are working to better understand the interplay between the immune system and metabolism. Barbara Maier and her team are researching the role of lymph nodes in the context of cancer. (Vienna, 5 September 2023) The ERC grants are among the most prestigious and competitive research grants offered ...

Faster postal service linked to better voter turnout

2023-09-05
PULLMAN, Wash. – A more efficient U.S. Postal Service can increase voter turnout in all states regardless of their mail voting laws, according to a Washington State University study. WSU researcher Michael Ritter analyzed election data from 2012 through 2020, when the pandemic encouraged many more people than usual to vote by mail. He found that in general more accessible mail voting laws, such as universal mail-in voting and no-excuse mail voting, increased the probability that individuals would vote. Restrictive laws, such as requiring ...

Scientists synthesize new organometallic “sandwich” compound capable of holding more electrons

Scientists synthesize new organometallic “sandwich” compound capable of holding more electrons
2023-09-05
Organometallic compounds, molecules made up of metal atoms and organic molecules, are often used to accelerate chemical reactions and have played a significant role in advancing the field of chemistry.  Metallocenes, a type of organometallic compound, are known for their versatility and special "sandwich" structure. Their discovery was a significant contribution to the field of organometallic chemistry and led to the awarding of the Nobel Prize in Chemistry in 1973 to the scientists who discovered and explained their sandwich structure.  The ...

LAST 30 PRESS RELEASES:

New route to ‘quantum spin liquid’ materials discovered for first time

Chang’e-6 basalts offer insights on lunar farside volcanism

Chang’e-6 lunar samples reveal 2.83-billion-year-old basalt with depleted mantle source

Zinc deficiency promotes Acinetobacter lung infection: study

How optogenetics can put the brakes on epilepsy seizures

Children exposed to antiseizure meds during pregnancy face neurodevelopmental risks, Drexel study finds

Adding immunotherapy to neoadjuvant chemoradiation may improve outcomes in esophageal cancer

Scientists transform blood into regenerative materials, paving the way for personalized, blood-based, 3D-printed implants

Maarja Öpik to take up the position of New Phytologist Editor-in-Chief from January 2025

Mountain lions coexist with outdoor recreationists by taking the night shift

Students who use dating apps take more risks with their sexual health

Breakthrough idea for CCU technology commercialization from 'carbon cycle of the earth'

Keck Hospital of USC earns an ‘A’ Hospital Safety Grade from The Leapfrog Group

Depression research pioneer Dr. Philip Gold maps disease's full-body impact

Rapid growth of global wildland-urban interface associated with wildfire risk, study shows

Generation of rat offspring from ovarian oocytes by Cross-species transplantation

Duke-NUS scientists develop novel plug-and-play test to evaluate T cell immunotherapy effectiveness

Compound metalens achieves distortion-free imaging with wide field of view

Age on the molecular level: showing changes through proteins

Label distribution similarity-based noise correction for crowdsourcing

The Lancet: Without immediate action nearly 260 million people in the USA predicted to have overweight or obesity by 2050

Diabetes medication may be effective in helping people drink less alcohol

US over 40s could live extra 5 years if they were all as active as top 25% of population

Limit hospital emissions by using short AI prompts - study

UT Health San Antonio ranks at the top 5% globally among universities for clinical medicine research

Fayetteville police positive about partnership with social workers

Optical biosensor rapidly detects monkeypox virus

New drug targets for Alzheimer’s identified from cerebrospinal fluid

Neuro-oncology experts reveal how to use AI to improve brain cancer diagnosis, monitoring, treatment

Argonne to explore novel ways to fight cancer and transform vaccine discovery with over $21 million from ARPA-H

[Press-News.org] Scammers can abuse security flaws in email forwarding to impersonate high-profile domains
Some of the domains vulnerable include Mastercard, The Washington Post and the Department of State