[exim] Tainted search query is not properly quoted

2023-03-26 Thread Martin D Kealey via Exim-users
On Sun, 19 Mar 2023, 23:00 , Odhiambo Washington wrote: > set acl_m_dontcare = ${lookup sqlite {INSERT INTO greylist \ > VALUES ( '$acl_m_greyident', \ > '${eval10:$tod_epoch+300}', \ > '${quote_sqlite:$sender_host_address}', \ > '${quote_sqlite:$sender_helo_name}' );}} > It's not obvious t

Re: [exim] Tainted search query is not properly quoted

2023-03-20 Thread Odhiambo Washington via Exim-users
On Mon, Mar 20, 2023 at 7:27 PM Jeremy Harris via Exim-users < exim-users@exim.org> wrote: > On 20/03/2023 15:14, Odhiambo Washington via Exim-users wrote: > > What mod do I need to make on it? > > Quote it. Like you already are for $sender_helo_name. > -- > Cheers, >Jeremy > That has now el

Re: [exim] Tainted search query is not properly quoted

2023-03-20 Thread Jeremy Harris via Exim-users
On 20/03/2023 15:14, Odhiambo Washington via Exim-users wrote: What mod do I need to make on it? Quote it. Like you already are for $sender_helo_name. -- Cheers, Jeremy -- ## List details at https://lists.exim.org/mailman/listinfo/exim-users ## Exim details at http://www.exim.org/ ## Pleas

Re: [exim] Tainted search query is not properly quoted

2023-03-20 Thread Odhiambo Washington via Exim-users
On Sun, Mar 19, 2023 at 2:31 PM Jeremy Harris via Exim-users < exim-users@exim.org> wrote: > On 19/03/2023 10:58, Odhiambo Washington via Exim-users wrote: > > warn condition= ${if eq {$acl_m_greyexpiry}{} {1}} > > set acl_m_dontcare = ${lookup sqlite {INSERT INTO greyl

Re: [exim] Tainted search query is not properly quoted

2023-03-19 Thread Jeremy Harris via Exim-users
On 19/03/2023 10:58, Odhiambo Washington via Exim-users wrote: warn condition= ${if eq {$acl_m_greyexpiry}{} {1}} set acl_m_dontcare = ${lookup sqlite {INSERT INTO greylist \ VALUES ( '$acl_m_greyident', \ '${eval10:$tod_ep

[exim] Tainted search query is not properly quoted

2023-03-19 Thread Odhiambo Washington via Exim-users
I am missing a little something in my config for greylisting. Exim-4.96 here. 2023-03-19 13:53:21 1pdqf6-000LgR-0z tainted search query is not properly quoted (ACL warn, /etc/exim/exim-greylist.conf.inc 124): INSERT INTO greylist VALUES ( 'ecpeUlXRs7cHPrkaiW5j', '1679223501', '74.6.132.40', ' soni