In the course of a research project in collaboration with the SEC Consult Vulnerability Lab, Timo Longin (@timolongin) - known for SMTP smuggling - discovered two exotic email spoofing vulnerabilities in Apple iCloud's emailing infrastructure.
At the end of 2023 SMTP smuggling made a dramatic entrance, allowing email spoofing for millions of email servers worldwide. Ever wanted to send emails as admin@outlook.com while still passing SPF checks? SMTP smuggling had you covered!
However, in 2024, most SMTP implementations adapted, and released security updates for their software. Does this mean the end of SMTP smuggling? Or does this attack have more to offer?
Let's dive into a case study of Apple iCloud's SMTP parsing jungle and try to spoof emails once more!
Note: This blog post is related to SMTP Smuggling - Spoofing E-Mails Worldwide. For additional contextual and background information, we recommend reading it first.
1. TL;DR
Even though no novel techniques for traditional SMTP smuggling were discovered, a subclass of email spoofing was explored - header smuggling. Again highlighting the parsing discrepancies in SMTP implementations, header smuggling builds upon the lessons of its bigger brother SMTP smuggling. Based on a case study of Apple iCloud's emailing services, we once again reveal the dangers of trusting emails by being able to send messages from arbitrary icloud.com addresses.
2. SMTP Smuggling Recap
First of all, let's have a short recap on SMTP smuggling. With traditional SMTP smuggling, we exploited interpretation differences of the SMTP protocol between outbound (sending) and inbound (receiving) SMTP servers. More specifically, we capitalized on the fact that lots of SMTP implementations deviated from RFCs, leading to different understandings of the so-called end-of-data sequence. Since the end-of-data sequence indicates where the message data ends, we could achieve the following between vulnerable outbound and inbound SMTP servers (figure 1).


















