Collected research
Smuggling SMTP through open HTTP proxies
An open HTTP proxy in a web app can be aimed at port 25, where the SMTP server reads each CRLF-terminated HTTP header as a command. IIS SMTP and sendmail logs show an injected QUIT executing. Full hijack is blocked only by the header validation built into XMLHTTP, PHP include and Java HttpUrlConnection.
Record
- Researcher
- Mike Zusman
- Published by
- schmoil.blogspot.com
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Mike Zusman, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .