Re: [exim] bypassing exim string expansion with invalid addr…

Top Page
Delete this message
Reply to this message
Author: Jeremy Harris
Date:  
To: exim-users
Subject: Re: [exim] bypassing exim string expansion with invalid addresses
On 13/03/2019 11:43, Graeme Fowler via Exim-users wrote:
> On 13 Mar 2019, at 09:55, Cyborg via Exim-users <exim-users@???> wrote:
>> I forgot to add the "attack" pattern:
>>
>> From: "ONLINE PHARMACY" <guclxfh@???>
>
> Valid per RFC5322.
>
>>       R="CANADA-DRUGSTORE" guclxfh@???>"

>
> Invalid per RFC5322. If it’s invalid, addresses cannot be extracted. We can only code against the valid format, as forms of invalidity are for all practical purposes infinite.



You *could* check the validity, using "verify = header_syntax".
--
Cheers,
Jeremy