On Sat, Jan 06, 2024 at 14:47:59 -0500, Wietse Venema via Postfix-users wrote:
> Damian:
> > If I remember correctly, on the wire there was \r\n\r\n.\r\r\n
>  
> Viktor Dukhovni:
> > Does that also need to be more strict? :-(
> 
> Indeed, and as usual the fix is trivial. This process is backwards,
> it is what we get with publication before the analysis, tooling,
> and software fixes are complete.


Extended the author's test suite with "CRCRLF" tests and indeed they pass:

https://github.com/The-Login/SMTP-Smuggling-Tools/pull/4

(with smtpd_forbid_bare_newline=yes but smtpd_forbid_unauth_pipelining=no)


        Geert


_______________________________________________
Postfix-users mailing list -- postfix-users@postfix.org
To unsubscribe send an email to postfix-users-le...@postfix.org

Reply via email to