Loading…
8 August | Hyderabad, India
Learn More and Register To Attend

The Sched app allows you to build your schedule, but it is not a substitute for event registration. To participate in the sessions, you must be registered for OpenSSF Community Day India 2025. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in India Standard Time. To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.

Schedule is subject to change.
Monday August 4, 2025 16:15 - 16:35 IST
Email remains a mission-critical service in both government and private sectors, and Zimbra—one of the most widely used open-source mail platforms—exposes real-world security challenges in open infrastructure.

This talk explores several critical vulnerabilities discovered in Zimbra, including a pre-auth RCE via SMTP command handling, an SSRF that enables remote shell access through internal proxy chaining, and a 2FA bypass that weakens authentication. These reflect systemic issues in open-source security at scale.

I’ll also introduce the Kobold Letter attack—an effective email parsing exploit that bypasses UI logic in Zimbra, Gmail, and Outlook using invisible formatting to aid phishing. This points to the urgent need for better mail parsing standards.

The session will blend offensive insights with defense: how these flaws were disclosed, mitigated, and what OSS maintainers can do to secure their stacks earlier. It’s ideal for red teamers, defenders, and those securing collaborative infrastructure.
Speakers
avatar for Ashish Kataria

Ashish Kataria

Security Architect Engineer, Synacor Inc.
Ashish is the head of security at Zimbra, overseeing vulnerability analysis,triage,and remediation for the widely deployed open-source Zimbra Collaboration Suite. He has led the resolution of high-impact CVEs and contributed to hardening against threats like the Kobold Letter attack... Read More →
Monday August 4, 2025 16:15 - 16:35 IST
Meeting Room 1 + 2

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link