[Esa-l] New variant of Hybris?

John D. Hardin jhardin at wolfenet.com
Tue Jan 2 20:49:16 PST 2001

On Tue, 2 Jan 2001, Karl Dunn wrote:

> I think this trick can be used to send ANY type of attachment past
> the filters: no body, just a nasty atachment.  We should run such
> stuff through the same perl script as attachments that FOLLOW a
> body.  No?

Sorry, I wasn't being clear there. I should have said, "no body text".
There was a text/plain MIME body part, with no content.

The sanitizer will sanitize a message that consists of only an

