3 ms·
I don't understand the hate against Timo. It's pretty obvious from the article that he only thought about the recipient side and not about the sender (postfix).
by e38383 3y ago
I don't understand the hate against Timo. It's pretty obvious from the article that he only thought about the recipient side and not about the sender (postfix). Postfix does behave wrong (according to e.g. RFC 2822 section 2.3), but it still was not in scope of the article.
The disclosure did go to the parties who he (or SEC Consult) seemed vulnerable.
If anything it just shows that Wietse have a way better understanding of SMTP than most of us normal humans.
- Aissen 3y agoQuoting the parent SEC Consult article: > This might not seem bad at first, but looking at affected SMTP software on the Internet is a different story. After testing some popular e-mail software in their default configuration, it turned out that Postfix and Sendmail fulfil the requirements, are affected and can be smuggled to. Speaking globally, this is a lot (figure 31)! It seems like Postfix was properly identified as a party to this issue.