top | item 38729233

(no title)

oori | 2 years ago

Strange they didn’t wait with this announcement a week or two, to allow proper holiday to fellow developers.

From postfix - “Days before a 10+ day holiday break and associated production change freeze, SEC Consult has published an email spoofing attack that involves a composition of email services with specific differences in the way they handle line endings other than <CR><LF>.

Unfortunately, criticial information provided by the researcher was not passed on to Postfix maintainers before publication of the attack, otherwise we would certainly have convinced SEC Consult to change their time schedule until after people had a chance to update their Postfix systems. ” - https://www.postfix.org/smtp-smuggling.html

discuss

order

varjag|2 years ago

Postfix pays no bounties, our dear ethical hackers could not be arsed.

Aachen|2 years ago

[deleted]