This is the test cases used in A Multifaceted Study on the Use of TLS and Auto-detect in Email Ecosystems. Read the paper for more details.
To accommodate different syntax, you will see there are three folders with the respective protocols.
- T1: STARTTLS stripping
- T2: Replace incoming ServerHello in TLS negotiation
- T3: Reject STARTTLS command
- T4: Disrupt a complete TLS handshake
-
Setup the mitmproxy according to their official website.
-
Modify the mitmproxy with the below command
git clone https://github.com/tls-downgrade/email-security.git
cp -r imap/ pop3/ smtp/ ./mitmproxy
cp next_layer.py ./mitmproxy/addons/
- Run the mitmproxy with the following command:
mitmproxy --set spoof-source-address --ssl-insecure --mode transparent --showhost -s <folder/file.py>