Re: [Exim] nessus security report

Top Page
Delete this message
Reply to this message
Author: Philip Hazel
Date:  
To: exim-users
Subject: Re: [Exim] nessus security report
On Fri, 19 May 2000, Peter Radcliffe wrote:

> | is a valid character in a local part as far as I know.


Yup. See the comments in the Exim manual about recognizing pipes in
alias files.

> |address isn't a problem, exim doesn't pass things to shell unless you
> make it do that, and if you do you have to be careful about characters
> in local parts.


Quite. A local part in an incoming address beginning with | doesn't
cause Exim to treat it as a pipe command. That would be a Really Silly
thing to do, wouldn't it? Deliveries to pipe (and files) can occur only
as a result of aliasing or forwarding or filtering.

-- 
Philip Hazel            University of Cambridge Computing Service,
ph10@???      Cambridge, England. Phone: +44 1223 334714.