@dragonfrog @badkeys No, the private key was never published by t-systems, but it's so weak that it's very easy to crack. OP cracked and published the private key.
millie@infosec.exchange
@millie@infosec.exchange
Indlæg
-
I reported an insecure DKIM key to Deutsche Telekom / T-Systems. -
I reported an insecure DKIM key to Deutsche Telekom / T-Systems.@dragonfrog @badkeys Most people might not be fluent in base64-encoded ASN.1, but a trained eye can see that it's the same key.
Hint: A sufficiently strong RSA key cannot possibly be that short, and you know it's a DER-encoded pubkey because it starts with "ME" and ends with "AQAB" (0x10001, common RSA public exponent)