Project

General

Profile

Actions

Feature #4386

closed
GD PA

Support for RFC2231

Feature #4386: Support for RFC2231

Added by Gatewatcher Dev Team about 5 years ago. Updated over 3 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:
C, Protocol

Description

We noticed a lack of support for multiline header attributes in mime documents as defined in RFC2231 (standard track).
This RFC documents a way to split header attributes across multiple lines, so that the line length remains short.
This wrapping is implemented by some popular MUA, including Thunderbird. Lack of support for this RFC results in Suricata not noticing/storing email attachments with filenames wrapped that way (filename*0=, filename*1=...).
This can also be considered as a evasion technique, although this is a standard track RFC.

We attached a pcap file containing an email attachment ignored by Suricata.

Thank you,

Cheers,
Florian Maury


Files

exemple_mime_sans_name_rfc.pcap (82.3 KB) exemple_mime_sans_name_rfc.pcap Gatewatcher Dev Team, 03/09/2021 09:17 AM

Subtasks 1 (0 open1 closed)

Feature #5478: Support for RFC2231 (6.0.x backport)ClosedPhilippe AntoineActions

PA Updated by Philippe Antoine almost 5 years ago Actions #1

  • Status changed from New to In Review
  • Target version set to 7.0.0-beta1

VJ Updated by Victor Julien over 4 years ago Actions #2

  • Assignee set to Philippe Antoine

PA Updated by Philippe Antoine over 4 years ago Actions #3

  • Status changed from In Review to Closed

VJ Updated by Victor Julien over 3 years ago Actions #4

  • Status changed from Closed to Resolved
  • Label Needs backport to 6.0 added

PA Updated by Philippe Antoine over 3 years ago Actions #5

  • Subtask #5478 added

VJ Updated by Victor Julien over 3 years ago Actions #6

  • Label deleted (Needs backport to 6.0)

PA Updated by Philippe Antoine over 3 years ago Actions #7

  • Status changed from Resolved to Closed
Actions

Also available in: PDF Atom