Category: IT|Jan 5, 2025 | Author: Admin

Over 3 million mail servers without encryption exposed to sniffing attacks

Share on

Over three million POP3 and IMAP mail servers without TLS encryption are currently exposed on the Internet and vulnerable to network sniffing attacks.

Over 3 million mail servers without encryption exposed to sniffing attacks

Over three million POP3 and IMAP mail servers without TLS encryption are currently exposed on the Internet and vulnerable to network sniffing attacks.

 

IMAP and POP3 are two methods for accessing email on mail servers. IMAP is recommended for checking emails from multiple devices, such as phones and laptops because it keeps your messages on the server and synchronizes them between devices. POP3, on the other hand, downloads emails from the server, making them accessible only from the device where they were downloaded.

 

It should also be noted that many hosting companies configure POP3 or IMAP services by default, even if no users use them.

 

The TLS secure communication protocol helps secure users' information while exchanging and accessing their emails over the Internet through client/server applications. However, when TLS encryption is not enabled, their messages' contents and credentials are sent in clear text, exposing them to eavesdropping network sniffing attacks.

 

As scans from the ShadowServer security threat monitoring platform Shadowserver show, around 3.3 million hosts are running POP3/IMAP services without TLS encryption enabled and expose usernames and passwords in plain text when transmitted over the Internet.

 

ShadowServer is now notifying mail server operators that their POP3/IMAP servers do not have TLS enabled, exposing users' unencrypted usernames and passwords to sniffing attacks.

 

"This means that passwords used for mail access may be intercepted by a network sniffer. Additionally, service exposure may enable password-guessing attacks against the server," Shadowserver said.

 

"If you receive this report from us, please enable TLS support for IMAP as well as consider whether the service needs to be enabled at all or moved behind a VPN."

 

​The original TLS 1.0 specification and its successor, TLS 1.1, have been used for nearly two decades, with TLS 1.0 being introduced in 1999 and TLS 1.1 in 2006. After extensive discussions and the development of 28 protocol drafts, the Internet Engineering Task Force (IETF) approved TLS 1.3, the next major version of the TLS protocol, in March 2018.

 

In a coordinated announcement in October 2018, Microsoft, Google, Apple, and Mozilla said they would retire the insecure TLS 1.0 and TLS 1.1 protocols in the first half of 2020. Microsoft began enabling TLS 1.3 by default in the latest Windows 10 Insider builds starting in August 2020.

 

In January 2021, the NSA also provided guidance on identifying and replacing outdated TLS protocol versions and configurations with modern, secure alternatives.

 

"Obsolete configurations provide adversaries access to sensitive operational traffic using a variety of techniques, such as passive decryption and modification of traffic through man-in-the-middle attacks," the NSA said.

 

"Attackers can exploit outdated transport layer security (TLS) protocol configurations to gain access to sensitive data with very few skills required."

Sponsored Ads:

Comments:


Cloudflare-12-06-25.png

Google Cloud and Cloudflare hit by widespread service outages

Category: IT|Jun 12, 2025 | Author: Admin
Outlook-11-06-25.png

Microsoft Outlook to block more risky attachments used in attacks

Category: Microsoft|Jun 11, 2025 | Author: Admin
Google_headpic-10-06-25.png

Google patched bug leaking phone numbers tied to accounts

Category: Google|Jun 10, 2025 | Author: Admin
Vodafone-headpic-09-06-25.png

Germany fines Vodafone $51 million for privacy, security breaches

Category: IT|Jun 9, 2025 | Author: Admin
Microsoft_logo-08-06-25.png

Microsoft unveils free EU cybersecurity program for governments

Category: Microsoft|Jun 8, 2025 | Author: Admin
FBI__headpic-07-06-25.jpg

Play ransomware breached 900 victims, including critical orgs

Category: IT|Jun 7, 2025 | Author: Admin
Cisco-06-06-25.png

Cisco warns of ISE and CCP flaws with public exploit code

Category: IT|Jun 6, 2025 | Author: Admin
Tu-160_strategic_bomber_aircraft-05-06-25.png

Ukraine claims it hacked Tupolev, Russia’s strategic warplane maker

Category: General|Jun 5, 2025 | Author: Admin
salesforce-04-06-25.png

Hackers target Salesforce accounts in data extortion attacks

Category: Google|Jun 4, 2025 | Author: Admin
logo.png

Mozilla launches new system to detect Firefox crypto drainer add-ons

Category: IT|Jun 3, 2025 | Author: Admin
Google_Chrome-02-06-25.png

Google Chrome to distrust Chunghwa Telecom, Netlock certificates in August

Category: Google|Jun 2, 2025 | Author: Admin
Cisco-logo-01-06-25.png

Exploit details for max severity Cisco IOS XE flaw now public

Category: IT|Jun 1, 2025 | Author: Admin
firefox-header-31-05-25.png

Mozilla releases Firefox 139.0.1 update to fix artifacts on Nvidia GPUs

Category: IT|May 31, 2025 | Author: Admin
microsoft-notepad-30-05-25.png

Microsoft now testing Notepad text formatting in Windows 11

Category: Microsoft|May 30, 2025 | Author: Admin
Windows_11_headpic-29-05-25.png

Windows 11 might fail to start after installing KB5058405

Category: Microsoft|May 29, 2025 | Author: Admin
more