Re: SMTP Smuggling
Matus UHLAR - fantomas <[email protected]>
| Newsgroups | gmane.mail.imap.courier.general |
|---|---|
| Message-ID | <[email protected]> |
>Christoph Mitasch via courier-users writes: >>« HTML content follows >> >>is Courier MTA affected by the new SMTP smuggling attack? >> >><URL:https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/>https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/ On 16.01.24 08:21, Sam Varshavchik wrote: >Nope, I see no issues here. > >Courier accepts either CRLF or LF as end of line sequence on inbound >mail, and correctly un-dot-stuffs the message. On the outbound side >Courier always uses CRLF, and always dot-stuff the message's contents. >This is elementary SMTP. Any attempt to use Courier to leverage this >exploit will fail. There's still question if courier can detect message that's been smuggled through server not aware of this issue and what will courier do if this happens. -- Matus UHLAR - fantomas, [email protected] ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. There's a long-standing bug relating to the x86 architecture that allows you to install Windows. -- Matthew D. Fuller _______________________________________________ courier-users mailing list [email protected] Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users