[oss-security] Re: New SMTP smuggling attack

2024-04-30 Thread nightmare . yeah27
On Mon, Apr 29, 2024 at 08:19:52PM GMT, Mark Esler wrote: > To mitigate future end-of-data sequence attacks, like SMTP > Smuggling, MTAs should comply with RFC 5321 section 4.1.1.4 [0] to > strip control characters other than , , , and in > the DATA section of SMTP messages. [...] > As per RFC

[oss-security] Re: Linux: Disabling network namespaces

2024-04-19 Thread nightmare . yeah27
On Wed, Apr 17, 2024 at 09:52:10AM GMT, Georgia Garcia wrote: > I just wanted to add that in the Ubuntu Noble Numbat release we are > using AppArmor to restrict unprivileged user namespaces. > Applications that don't have an AppArmor profile will use a default > profile which denies the use of ca