HostedDB - Dedicated UNIX Servers

-->
IT Baseline Protection Manual T 4.37 Lack of time authenticity in E-mail

T 4.37 Lack of time authenticity in E-mail

An E-mail can contain various information about time, such as the time a message was sent, the transmission time or the time it was received. These are not tamperproof, though. For example, the time a message was sent can be falsified by adjusting the system time on the computer from which the message was sent. While an E-mail is on it's way from the sender to the recipient, the mail header, in particular the entries for time, date and address of the mail server, can be falsified at will. A further attack to be mentioned is the systematic and purposeful corruption and diversion of SMTP packets.


© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
 
home