Web Hack List

Collected research

Smuggling SMTP through open HTTP proxies

An open HTTP proxy in a web app can be aimed at port 25, where the SMTP server reads each CRLF-terminated HTTP header as a command. IIS SMTP and sendmail logs show an injected QUIT executing. Full hijack is blocked only by the header validation built into XMLHTTP, PHP include and Java HttpUrlConnection.

Record

Researcher
Mike Zusman
Published by
schmoil.blogspot.com
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mike Zusman, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .