[tor-talk] TLS/SSL SMTP MitM

Philipp Winter phw at nymity.ch
Wed Mar 12 14:58:01 UTC 2014


On Mon, Mar 10, 2014 at 06:43:31PM +0000, Gordon Morehouse wrote:
> I have been doing some testing of sending email over Tor and today ran
> into a definite BadExit (but not flagged, clearly) because there was a
> blatant MitM attempt on three separate occasions when I initiated a
> TLS/SSL SMTP connection to my mail provider.  

Given that you used SSL SMTP, I assume your connection went to port 465?

I probed all ~400 currently available exit relays which allow exiting to port
465 but could not spot any MitM attacks yet.

Cheers,
Philipp


More information about the tor-talk mailing list