[Esd-l] Detection rule for sendmail header exploit

John D. Hardin jhardin at impsec.org
Sat Mar 8 19:42:07 PST 2003

On Sat, 8 Mar 2003, Joe Steele wrote:

> To be effective without casting too large a net, each address in a
> list needs to be scanned separately.  Attempting to do this with a
> regular expression could get complicated.


> Another point to note is that the RE should begin with the
> following in order to trap all headers for which sendmail is
> vulnerable:
> * ^((resent-)?(sender|from|(reply-)?to|cc|bcc)\
>     |(errors|disposition-notification|apparently)-to):

Thanks! I've incorporated that.

