OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Regex Question - UCE

From: Adam Levin (alevinaudible.com)
Date: Fri Apr 04 2003 - 09:46:08 CST


On Fri, 4 Apr 2003, Liviu Daia wrote:
> On 4 April 2003, Jeffrey Posluns <jeff-listsposluns.com> wrote:
> > I don't think there's a regular use for a base64 encoded html/text
> > type message, but I wouldn't put it past Microsoft to do that in
> > Outlook or Outlook Express for some fancy html email.
> >
> > Is anyone aware of:
> > 1. A situation that is valid for base64 encoded html/text type emails?
>
> Yes, the content type and encoding are orthogonal to one another.
> Most MUAs are chosing the latter based on the size of the encoded
> attachment compared to the initial size, not based on type.

I'd at least like to put in a WARN to see what I can catch.

> > 2. A way to do a header check for more than one header at the same
> > time?
>
> Not without an external content filter.

Does Postfix not allow multiline matching or PCRE_DOTALL with the 's'
suffix? I've been playing with various regex in my body_checks (wouldn't
these content-type and encoding lines appears as part of the body, not the
header), but I can't seem to get any multiline stuff working.

-Adam

Adam Levin, Senior Unix Systems Administrator | http://www.audible.com/
Audible, Inc. /\
Wayne, NJ, 07470 \/ ASCII Ribbon Campaign
973-837-2797 /\ Say NO to HTML in email and news