OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: allow_min_user

From: Matt (mathmlists.ath.cx)
Date: Mon Aug 02 2004 - 17:40:48 CDT


> >
> > The RFC lets one get away with a lot of characters that are unlikely
> > to be accepted by actual implementations.
> >
>
> Just realized that check_recipient restrictions are applied before the
> address is subjected to the allow_min_user check, so it's all academic
> now. I'm still curious what the implications of allowing this are
> though.
>

 Put simply, a poorly written app/filter or whatever can misinterpret it
as a command option instead of an username/email address.

Matt