Web Hack List

Collected research

SMTP Injection via Recipient Email Address

A recipient address carrying CRLF, or the RFC 5322 folding white space and obsolete quoted pair line breaks, smuggles extra SMTP commands into the RCPT TO line, which pipelining mail servers then execute. Attackers can send arbitrary mail through vulnerable Ruby Mail, JavaMail and PHPMailer, or by injecting into the sender address divert the original confidential message to themselves.

Record

Researcher
Takeshi Terada
Published by
mbsd.jp
Format
Whitepaper
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Takeshi Terada, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .