4 ms·
A fun experiment for someone who isn't afraid of having their ISP, colocation provider, or VM provider terminate their account and/or sue them because ZOMG LOTS
by rwg 12y ago
A fun experiment for someone who isn't afraid of having their ISP, colocation provider, or VM provider terminate their account and/or sue them because ZOMG LOTS OF OUTBOUND TCP/25 CONNECTIONS MEANS A SPAMMER IS YOU:
• Take Google's list of mail domains they see (they offer a CSV file for download) and look up all of the mail exchangers for all of the domains.
• Remove duplicates from the list of MX hostnames.
• Write a short program that does the following for each of those mail exchangers:
- Connect to tcp/25, send a valid EHLO, and see if the server indicates that it supports STARTTLS.
- If it doesn't, disconnect and move on to the next hostname.
- Send STARTTLS and start a TLS session. Put a NULL cipher at the top of your client's ciphersuite list to see if anyone bites. Record the certificate chain the server sends.
- See if the leaf certificate is valid and if you can make it actually chain up to a trusted CA via the server's certificate chain.
- Disconnect.
You now have a list of some of the largest mail exchangers on the Internet, whether or not each one supports STARTTLS, and whether or not each one supplies a (valid) certificate that actually chains up to a CA anyone trusts. Write a blog post containing pretty graphs for these statistics. Poke fun at the most egregiously broken TLS configurations, certificates, and certificate chains you see. Idly wonder if the proliferation of (sometimes completely broken) opportunistic TLS with SMTP and the relative scarcity of authenticated TLS with SMTP will push passive attackers into becoming active attackers so they can continue to easily grab messages in-flight. Bemoan the broken CA system. Drink heavily. Dream.