LuKreme a écrit :
> On 14-Sep-2009, at 04:06, Ansgar Wiechers wrote:
>> On 2009-09-14 Markus Schönhaber wrote:
>>> Ansgar Wiechers:
>>>> It appears that Postfix considers addresses beginning with a dash as
>>>> invalid:
>>>
>>> http://www.postfix.org/postconf.5.html#allow_min_user
>>
>> Thanks.
> 
> Be sure and take the under-lying warning to heart. Addresses starting in
> '-' are quite dangerous.
> 

and gods with a wood face? come on.

such addresses are not dangerous, except if you still use silly code to
deliver mail. in which case your delivery agent have other
vulnerabilities (code injection attacks are too well known today).

after all, such addresses are (still) valid according to the standards.

Yes, such addresses are not needed. so it is safe to forbid them. but it
would be better if the standards were modified to "invalidate" them.

Reply via email to