[exim] Re: SMTP smuggling and Exim

2023-12-23 Thread Jeremy Harris via Exim-users
On 12/23/23 19:15, Ian Z via Exim-users wrote: On Sat, Dec 23, 2023 at 10:27:02AM +, Jeremy Harris via Exim-users wrote: Some changes in that direction are already available. An intriguing statement ;-) Available in 4.97, on master, on another branch? In the git master. Are there buil

[exim] Re: SMTP smuggling and Exim

2023-12-23 Thread Ian Z via Exim-users
On Sat, Dec 23, 2023 at 10:27:02AM +, Jeremy Harris via Exim-users wrote: > As is commonly the case, the major issue is compatibility with > non-standards-conforming systems which *was* needed in the past. > Tightening the screws may break existing installations. > Some changes in that direct

[exim] Re: SMTP smuggling and Exim

2023-12-23 Thread Cyborg via Exim-users
Am 22.12.23 um 11:37 schrieb Bjoern Franke via Exim-users: Hi, I didn't see anything in the archives regarding this: https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/ Ok, i have issues seeing this as an "attack" at all, as you just can use the "evil" FROM as

[exim] Re: SMTP smuggling and Exim

2023-12-23 Thread Jeremy Harris via Exim-users
On 12/22/23 10:37, Bjoern Franke via Exim-users wrote: exim is not mentioned, so it's not affected? There's discussion as to whether it's really a useful attack. Exim cannot be used as the first relay, but can be the second site. As is commonly the case, the major issue is compatibility with n

[exim] Re: SMTP smuggling and Exim

2023-12-23 Thread Klaus Ethgen via Exim-users
Hi, Am Fr den 22. Dez 2023 um 11:37 schrieb Bjoern Franke via Exim-users: > I didn't see anything in the archives regarding this: > > https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/ > > exim is not mentioned, so it's not affected? Well, there are two things why ex

[exim] SMTP smuggling and Exim

2023-12-23 Thread Bjoern Franke via Exim-users
Hi, I didn't see anything in the archives regarding this: https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/ exim is not mentioned, so it's not affected? Regards Bjoern -- ## subscription configuration (requires account): ## https://lists.exim.org/mailman3/postor