Collected research
SMTP Injection via Recipient Email Address
A recipient address carrying CRLF, or the RFC 5322 folding white space and obsolete quoted pair line breaks, smuggles extra SMTP commands into the RCPT TO line, which pipelining mail servers then execute. Attackers can send arbitrary mail through vulnerable Ruby Mail, JavaMail and PHPMailer, or by injecting into the sender address divert the original confidential message to themselves.
Record
- Researcher
- Takeshi Terada
- Published by
- mbsd.jp
- Format
- Whitepaper
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Takeshi Terada, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .