Other nomination
Splitting the email atom: exploiting parsers to bypass access controls
Many sites infer organisational membership from the domain part of an email address, which makes disagreement between email parsers a trust decision. This paper shows how RFC-permitted quoting and escapes, encoded-word headers, malformed Punycode and Unicode case-mapping overflows let a single address be delivered to the attacker while validating as another domain, producing access-control bypasses in widely used platforms and, in one case, remote code execution.
Record
- Researcher
- Gareth Heyes
- Published by
- PortSwigger Research
- Date
In the archive
Related sources
- Splitting the Email Atom Black Hat slides
- Splitting the Email Atom research materials
- Talk recording
- Talk recording
Tags
This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host.