Index | Thread | Search

From:
Omar Polo <op@omarpolo.com>
Subject:
Re: smtpd smuggling
To:
Claudio Jeker <cjeker@diehard.n-r-g.com>
Cc:
gilles@poolp.org, tech@openbsd.org
Date:
Sun, 28 Jan 2024 13:40:04 +0100

Download raw body.

Thread
On 2024/01/24 14:22:28 +0100, Claudio Jeker <cjeker@diehard.n-r-g.com> wrote:
> On Wed, Jan 24, 2024 at 11:24:01AM +0100, Omar Polo wrote:
> > I'd like to retract the diff.  While it worked for me for the vast
> > majority of the mails, I had a case of a fairly important mail being
> > rejected due to this strictness.  Fun thing: it was from amazon and
> > forwarded to me by a gmail address.
> > 
> > maybe we could be strict only with the "." hanling.
> 
> I'm surprised by this. I thought this was a solved issue since qmail
> enforces strict CRLF encoding and did this for a very very long time.
> See also http://pobox.com/~djb/docs/smtplf.html 

(sorry for the delay)

I'm surprised too.  More likely it's just a bug in my diff that I'm not
seeing.  Anyway, I wanted to let anyone who may have tried it about the
issue.

Also, thinking more about it, assuming we want the lax-newlines toggle,
it should better accept a table of addresses and not apply to the whole
listen directive.