Web Hack List

Collected research

MX Injection : Capturing and Exploiting Hidden Mail Servers

[MX Injection : Capturing and Exploiting Hidden Mail Servers] Web Security Articles

Vicente Aguilera Diaz's paper on MX Injection. A webmail application passes user input into IMAP or SMTP commands, so an injected carriage-return and line-feed ends the intended command and starts an attacker's own. That reaches a mail server no one can address directly, allowing arbitrary mailbox commands, mail relay and information disclosure from behind the web tier.

Record

Document
[MX Injection : Capturing and Exploiting Hidden Mail Servers] Web Security Articles
Researcher
Vicente Aguilera Diaz
Published by
webappsec.org
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Vicente Aguilera Diaz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .