註冊並分享邀請連結,可獲得影片播放與邀請獎勵。

Dan DiGangi
@dandigangi
加入 September 2010
4.9K 正在關注    4.9K 粉絲
this is interesting. sparked some thoughts about agents accessing email. smtp in particular. - smtp is the more risky vector. more parsing, more content types, etc. means more surface to hide attacks. - smtp auth is usually username/password vs APIs where you have tokens/scoping/oauth. - smtp defaults to not checking dmarc, dkim, spf for identity verification. so... if you dont setup this stuff, the agent doesnt honor it, and the receiving esps dont enforce it some really, really bad things can happen no matter how good your prompt is. phishing of course instantly comes to mind.
顯示更多