[exim] Infos: someone posted an none working exploit for ex…

Αρχική Σελίδα
Delete this message
Reply to this message
Συντάκτης: Cyborg
Ημερομηνία:  
Προς: exim-users
Καινούρια Θέματα: [exim] Security reminder on email address characters
Αντικείμενο: [exim] Infos: someone posted an none working exploit for exim

More Infos here:

https://www.redteam-pentesting.de/de/advisories/rt-sa-2013-001/-exim-with-dovecot-typical-misconfiguration-leads-to-remote-command-execution


but it's a dovecot problem as it seems. On the other hand "`" is not an
allowed char in an emailaddress..

How about just kicking those connection attempts by default with i.e.
"500 illegal chars used" ?

Marius