spf-discuss
[Top] [All Lists]

Re: SRS and AOL case folding

2004-03-23 07:36:56
On Tue, 23 Mar 2004, Shevek wrote:

I got a bounce from AOL with the case folded:

As long as you are running at least Mail::SRS version 0.30, then the case
folding is not a problem. You should get a warning in your logfile saying 
that an SRS bounce was received with case folded. There are a large number 
of unit tests for this feature.

Yes.  It works in the Python translation of Mail::SRS also.  This turned
out to be an attack that lasted for about an hour.  Someone was testing
the feasibility of guessing a cookie by brute force.

-- 
                        Stuart D. Gathman <stuart(_at_)bmsi(_dot_)com>
      Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
      "Very few of our customers are going to have a pure Unix
      or pure Windows environment." - Dennis Oldroyd, Microsoft Corporation


<Prev in Thread] Current Thread [Next in Thread>