/usr/share/sanitizer/testcases/results.def/sanitizer.boundary.ok is in sanitizer 1.76-5.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 | From bre Fri Jan 30 03:37:34 1998
Date: Wed, 13 Dec 2000 17:13:26 +0800
From: Admin <foo@bar.com>
Subject: Yet another MIME test
To: Admin <baz@bar.com>
Con(FOO)tent-Type: MULT(comment)I(c2)PA(c3)RT/ALTERNATIVE; boundary=Boundary_(THIS_DOESNT_GET_DROPPED)
X-Sanitizer: This message has been sanitized!
X-Sanitizer-URL: http://mailtools.anomy.net/
MIME-Version: 1.0
Content-Type: MULTIPART/ALTERNATIVE; boundary="MIMEStream=_+testing99"
Content-Transfer-Encoding: 8bit
--MIMEStream=_+testing99
Content-Type: application/DEFANGED-101; format=flowed; charset="us-ascii"
Content-Disposition: attachment; name="evil file_exe.DEFANGED-101"
Part one
--MIMEStream=_+testing99
Content-type: text/plain; charset=us-ascii
Part two
--
This message has been 'sanitized'. This means that potentially
dangerous content has been rewritten or removed. The following
log describes which actions were taken.
Sanitizer (start="0"):
ParseHeader ():
Detected obfuscated content-type header: con(foo)tent-type
Replaced MIME boundary: >>Boundary_<<
with: >>MIMEStream=_+testing99<<
Fixed invalid/unusable part encoding.
Part (pos="357"):
SanitizeFile (filename="evil file.exe", mimetype="text/plain"):
Match (rule="default"):
Enforced policy: defang
Replaced mime type with: application/DEFANGED-101
Replaced file name with: evil file_exe.DEFANGED-101
Part (pos="521"):
SanitizeFile (filename="unnamed.txt", mimetype="text/plain"):
Match (names="unnamed.txt", rule="2"):
Enforced policy: accept
Total modifications so far: 3
--MIMEStream=_+testing99--
*** Exit code was 0 ***
From bre Fri Jan 30 03:37:34 1998
Date: Wed, 13 Dec 2000 17:13:26 +0800
From: Admin <foo@bar.com>
Subject: Yet another MIME test
To: Admin <baz@bar.com>
X-Sanitizer: This message has been sanitized!
X-Sanitizer-URL: http://mailtools.anomy.net/
MIME-Version: 1.0
Content-Type: MULTIPART/ALTERNATIVE; boundary="MIMEStream=_+testing99"
Content-Transfer-Encoding: 8bit
--MIMEStream=_+testing99
Content-Type: application/DEFANGED-100; format=flowed; charset="us-ascii"
Content-Disposition: attachment; name="evil file_exe.DEFANGED-100"
Part one
--MIMEStream=_+testing99
Content-type: text/plain; charset=us-ascii
Part two
--
This message has been 'sanitized'. This means that potentially
dangerous content has been rewritten or removed. The following
log describes which actions were taken.
Sanitizer (start="0"):
Replaced MIME boundary: >>Boundary<<
with: >>MIMEStream=_+testing99<<
Part (pos="289"):
SanitizeFile (filename="evil file.exe", mimetype="text/plain"):
Match (rule="default"):
Enforced policy: defang
Replaced mime type with: application/DEFANGED-100
Replaced file name with: evil file_exe.DEFANGED-100
Part (pos="420"):
SanitizeFile (filename="unnamed.txt", mimetype="text/plain"):
Match (names="unnamed.txt", rule="2"):
Enforced policy: accept
Total modifications so far: 2
--MIMEStream=_+testing99--
*** Exit code was 0 ***
From bre Fri Jan 30 03:37:34 1998
Date: Wed, 13 Dec 2000 17:13:26 +0800
From: Admin <foo@bar.com>
Subject: Yet another MIME test
To: Admin <baz@bar.com>
X-Sanitizer: This message has been sanitized!
X-Sanitizer-URL: http://mailtools.anomy.net/
MIME-Version: 1.0
Content-Type: MULTIPART/ALTERNATIVE; boundary=Boundary
Content-Transfer-Encoding: 8bit
--------------------------------------------
This is crap
--------------------------------------------
--NotABoundary
--ReallyAFakeBoundary
--Boundary
Content-Type: application/DEFANGED-100; format=flowed; charset="us-ascii"
Content-Disposition: attachment; name="evil_exe.DEFANGED-100"
Part one
--Boundary
Content-type: text/plain; charset=us-ascii
Part two
--
This message has been 'sanitized'. This means that potentially
dangerous content has been rewritten or removed. The following
log describes which actions were taken.
Sanitizer (start="0"):
MIME boundary missing, guessed: >>Boundary<<
Part (pos="395"):
SanitizeFile (filename="evil.exe", mimetype="text/plain"):
Match (rule="default"):
Enforced policy: defang
Replaced mime type with: application/DEFANGED-100
Replaced file name with: evil_exe.DEFANGED-100
Part (pos="523"):
SanitizeFile (filename="unnamed.txt", mimetype="text/plain"):
Match (names="unnamed.txt", rule="2"):
Enforced policy: accept
Total modifications so far: 2
--Boundary--
*** Exit code was 0 ***
|