Link to home
Start Free TrialLog in
Avatar of Robert Silver
Robert SilverFlag for United States of America

asked on

can valid email addresses contain hacker commands embedded especially for sendmail servers?

I suspect that the RFC 2822  standards allow some shady email address sequences.
Can anyone confirm this and suggest a remedy to the problem?

I imagine I could validate and then do a check for any odd characters not typical
Perhaps sequences like  cmd\ blowupmymachine.exe@hurtme.com  may do something rather nasty.
Perhaps someone has some ideas about this particularly which of the nasty punctuation characters
make this possible
ASKER CERTIFIED SOLUTION
Avatar of jar3817
jar3817

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Robert Silver

ASKER

Again I still find it odd that  such email addresses are possible
320 character email addresses? unbelivable.