Web Hack List

Collected research

Splitting the email atom: exploiting parsers to bypass access controls

Many sites infer organisational membership from the domain part of an email address, which makes disagreement between email parsers a trust decision. This paper shows how RFC-permitted quoting and escapes, encoded-word headers, malformed Punycode and Unicode case-mapping overflows let a single address be delivered to the attacker while validating as another domain, producing access-control bypasses in widely used platforms and, in one case, remote code execution.

Record

Researcher
Gareth Heyes
Published by
PortSwigger Research
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .