Project

General

Profile

Actions

Feature #6296

open

smtp: BDAT chunking support incl MIME parsing

Added by Marko Jahnke 10 months ago. Updated 6 months ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:
Protocol

Description

If I got it right, the MIME part of SMTP messages is not parsed if the "BDAT" command is used for chunking.

In app-layer-smtp.c, the initialization of the MIME state data structure is only performed if the plain "DATA" command is used.
The SMTPProcessCommandBDAT function just seems to step over the lines following the BDAT command without any further processing.

If my observation is correct, I would like to suggest to implement it. If not, please close the ticket. Thanks.


Related issues 1 (1 open0 closed)

Related to Suricata - Task #6443: Suricon 2023 brainstormAssignedVictor JulienActions
Actions #1

Updated by Jason Ish 7 months ago

  • Related to Task #6443: Suricon 2023 brainstorm added
Actions #2

Updated by Victor Julien 7 months ago

  • Subject changed from Support MIME parsing in SMTP messages using BDAT chunking to smtp: BDAT chunking support incl MIME parsing
Actions #3

Updated by Victor Julien 7 months ago

  • Label Protocol added
Actions #4

Updated by Victor Julien 7 months ago

  • Status changed from New to Assigned
Actions #5

Updated by Ralf Meister 6 months ago

I have encountered the same issue as user maja and developed some patches that implements the BDAT command and passes the data to the MIME parser...

I would like to share these patches with you. How can this be done?

Actions #6

Updated by Andreas Herz 6 months ago

Ralf Meister wrote in #note-5:

I would like to share these patches with you. How can this be done?

We have put out this guide for contributing code to the project, see https://docs.suricata.io/en/latest/devguide/codebase/contributing/contribution-process.html for the details.

In a nutshell, create a PR on github towards Suricata with your changes following the guideline outlined in the documentation.

Actions #7

Updated by Sascha Steinbiss 6 months ago

I would also like to offer my assistance getting your contributions into Suricata, if there are still questions. Feel free to get in touch by simply replying here.

Actions

Also available in: Atom PDF