PMG 7.3-11 russian letters in domain name

MrBubbLes

New Member
Feb 27, 2024
2
0
1
Good day!
My first post is disappeared. Trying to post new one.

I have PMG as Exchange 2019 frontend.

My domain name, for example, is pxo-co.kz
For testing fishing case I made a cyrillyc domain with mailservice рхо-со.kz

If you see at the email addresses of both domains, you can see they are identical at first look.
Example:
somebody@pxo-co.kz - english letters
somebody@рхо-со.kz - cyrillyc letters

PMG and Exchange will accept such emails, and all enduser can do to determine which of them is wrong - copypaste it to the notepad and get something like this:
from=<xxx@xn----8sbp2bhi9a.kz
In outlook it looks like xxx@pxo-co.kz
In OWA it looks like xxx@xn----8sbp2bhi9a.kz
In PMG Syslog it looks like xxx@xn----8sbp2bhi9a.kz

Here is a part of PMG Syslog, with sensitive data removed:

https://pastebin.com/ZwdUzjHa

Question:
How can i filter such emails with PMG?
 
for reference, this type of attack is called a 'homograph attack' https://en.wikipedia.org/wiki/IDN_homograph_attack

and there are not really any easy mitigations for that in general (see the 'Defending against the attack' section on wikipedia)

you could block all punycode domains, but that might prevent real mails from coming in...
 
Last edited:

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!