New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ZEEK SMTP Header Parsing Issue #1352
Comments
Do you by chance have a pcap that illustrates it? That would help in tracking down the issue. |
Hi, We have proposed the following changes as explained in the below PR: Please let us know if you still need pcap ? Thanks. |
Hi, thanks for the PR. A pcap actually still would be helpful for reproduction - and for inclusion in the testsuite. Alternatively - it would be great if you could add a testcase to the PR :). Thank you very much, |
…ithub.com/theavgjojo/zeek * 'topic/oakljon/gh-1352-smtp-header-parsing' of https://github.com/theavgjojo/zeek: GH-1352: Added flag to stop processing SMTP headers in attached messages
messages (cherry picked from commit 25de6f2)
messages (cherry picked from commit 25de6f2)
messages (cherry picked from commit 25de6f2)
There is an issue with SMTP parsing where header extraction continues parsing into the body and attachments of emails. A common case which leads this issue to surface appears when emails are sent as attachments. If you have an attachment that itself is an email, the headers from the attached email will override headers parsed from the actual email.
This incidentally might be the cause of previously seen issues such as #254.
The text was updated successfully, but these errors were encountered: