Forensic Incident Replay
Step-by-step wire analysis of in-path STARTTLS stripping observed during SMTP transit.
Step 4 of 6: CRITICAL: STARTTLS STRIPPED
CRITICAL INCIDENT: The destination server legitimately offered STARTTLS encryption support. However, Hop 2 is an active adversary sitting directly on the transit link. The attacker intercepted the packet in mid-transit, deleted '250-STARTTLS', recalculated the TCP checksum, and forwarded the modified packet to our server. Our mail server was deceived into assuming encryption is not supported.
250-STARTTLS 250-PIPELINE 250-SIZE 3588000 250 8BITMIME
250-PIPELINE 250-SIZE 3588000 250 8BITMIME
CRITICAL: STARTTLS STRIPPED
Server 250 response intercepted. Adversary in the middle strips 250-STARTTLS keyword before forwarding to client.
Active downgrade attack suppresses encryption opportunity, tricking sending MTA into sending in unencrypted plaintext.
32 35 30 2d 50 49 50 45 4c 49 4e 45 0d 0a 32 35 30 2d 53 49 5a 45 20 33 35 38 38 30 30 30 0d 0a
250-PIPELINE 250-SIZE 3588000 [STARTTLS REMOVED BY MITM PROXY]