OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: AArgh! Broken MUAs and bounce messages

From: Victor Duchovni (Victor.DuchovniMorganStanley.com)
Date: Fri Dec 08 2006 - 09:40:38 CST


On Fri, Dec 08, 2006 at 10:31:34AM -0500, Wietse Venema wrote:

> Apparently, some MUA software interprets Postfix bounce messages
> as HTML, and therefore removes "<postmaster>" from the bounce
> message text.
>
> Apparently, what they see is this:
>
> For further assistance, please send mail to
>
> The Postfix program
>
> This is based on one single report from a random stranger who asked
> me for assistance with an email problem. The report could be wrong.

Broken web mail perhaps? (Serious cross-site HTML Injection
vulnerability). Alternatively the problem may arise when the bounce
report is converted to HTML for forwarding. I have a hard time believing
that a stand-alone (not sloppy webmail) MUA mangles text/plain with
HTML meta-characters...

--
        Viktor.

Disclaimer: off-list followups get on-list replies or get ignored.
Please do not ignore the "Reply-To" header.

To unsubscribe from the postfix-users list, visit
http://www.postfix.org/lists.html or click the link below:
<mailto:majordomopostfix.org?body=unsubscribe%20postfix-users>

If my response solves your problem, the best way to thank me is to not
send an "it worked, thanks" follow-up. If you must respond, please put
"It worked, thanks" in the "Subject" so I can delete these quickly.