Movatterモバイル変換


[0]ホーム

URL:


HomeE-mail Header Injection Vulnerabilities
Article
Licensed
UnlicensedRequires Authentication

E-mail Header Injection Vulnerabilities

  • Sai Prashanth Chandramouli

    Sai Prashanth Chandramouli has a Masters in Computer Science from Arizona State University, with a thesis on E-mail Header Injection vulnerability, which he developed under the guidance of Dr. Adam Doupé. His interests include web security and computational creativity.

    Arizona State University, P.O. Box 878809, Tempe, AZ 85287-8809, UnitedStates of America

    ,Ziming Zhao

    Dr. Ziming Zhao is an assistant research professor in the School of Computing, Informatics, and Decision Systems Engineering, Ira A. Fulton Schools of Engineering, Arizona State University. His research interests include system and network security and cybercrime analysis. Dr. Zhao received a Ph.D in Computer Science from Arizona State University (ASU). He is a member of IEEE and the ACM.

    Arizona State University, P.O. Box 878809, Tempe, AZ 85287-8809, UnitedStates of America

    ,Adam Doupé

    Dr. Adam Doupé is an Assistant Professor in the School of Computing, Informatics, and Decision Systems Engineering at Arizona State University. His research interests include vulnerability analysis, web security, mobile security, and hacking competitions, which has been supported by the National Science Foundation.

    Arizona State University, P.O. Box 878809, Tempe, AZ 85287-8809, UnitedStates of America

    EMAIL logo
    andGail-Joon Ahn

    Dr. Gail-Joon Ahn is currently a professor of computer science and engineering in the School of Computing, Informatics, and Decision Systems Engineering and the director of Center for Cybersecurity and Digital Forensics, Arizona State University. His research interests include information and systems security, vulnerability and risk management, access control, and security architecture for distributed systems, which has been supported by National Science Foundation, Department of Defense, Office of Naval Research, Army Research Office, Department of Justice, and private sectors including Allstate, Bank of America, Hewlett Packard, Microsoft, Robert Wood Johnson Foundation, Cisco, GoDaddy, and Intel. He received the Department of Energy Early Career Investigator Award and the Educator of the Year Award given by the Federal Information Systems Security Educators Association in 2005.

    Arizona State University, P.O. Box 878809, Tempe, AZ 85287-8809, UnitedStates of America

Published/Copyright:March 15, 2017

Abstract

E-mail Header Injection vulnerability is a class of vulnerability that can occur in web applications that use user input to construct e-mailmessages. E-mail Header Injection is possible when the mailing script fails to check for the presence of e-mail headers in user input (eitherform fields or URL parameters). The vulnerability exists in the reference implementation of the built-in mailfunctionality in popular languages such as PHP, Java, Python, and Ruby. With the proper injection string, thisvulnerability can be exploited to inject additional headers, modify existing headers, and alter the content of thee-mail.

About the authors

Sai Prashanth Chandramouli

Sai Prashanth Chandramouli has a Masters in Computer Science from Arizona State University, with a thesis on E-mail Header Injection vulnerability, which he developed under the guidance of Dr. Adam Doupé. His interests include web security and computational creativity.

Arizona State University, P.O. Box 878809, Tempe, AZ 85287-8809, UnitedStates of America

Ziming Zhao

Dr. Ziming Zhao is an assistant research professor in the School of Computing, Informatics, and Decision Systems Engineering, Ira A. Fulton Schools of Engineering, Arizona State University. His research interests include system and network security and cybercrime analysis. Dr. Zhao received a Ph.D in Computer Science from Arizona State University (ASU). He is a member of IEEE and the ACM.

Arizona State University, P.O. Box 878809, Tempe, AZ 85287-8809, UnitedStates of America

Adam Doupé

Dr. Adam Doupé is an Assistant Professor in the School of Computing, Informatics, and Decision Systems Engineering at Arizona State University. His research interests include vulnerability analysis, web security, mobile security, and hacking competitions, which has been supported by the National Science Foundation.

Arizona State University, P.O. Box 878809, Tempe, AZ 85287-8809, UnitedStates of America

Gail-Joon Ahn

Dr. Gail-Joon Ahn is currently a professor of computer science and engineering in the School of Computing, Informatics, and Decision Systems Engineering and the director of Center for Cybersecurity and Digital Forensics, Arizona State University. His research interests include information and systems security, vulnerability and risk management, access control, and security architecture for distributed systems, which has been supported by National Science Foundation, Department of Defense, Office of Naval Research, Army Research Office, Department of Justice, and private sectors including Allstate, Bank of America, Hewlett Packard, Microsoft, Robert Wood Johnson Foundation, Cisco, GoDaddy, and Intel. He received the Department of Energy Early Career Investigator Award and the Educator of the Year Award given by the Federal Information Systems Security Educators Association in 2005.

Arizona State University, P.O. Box 878809, Tempe, AZ 85287-8809, UnitedStates of America

Received:2016-8-9
Accepted:2016-11-16
Published Online:2017-3-15
Published in Print:2017-4-20

©2017 Walter de Gruyter Berlin/Boston

You are currently not able to access this content.
Stay updated on our offers and services
Subscribe to our newsletter
Institutional Access
How does access work?
Have an idea on how to improve our website?
Please write us.
© 2025 De Gruyter Brill
Downloaded on 19.4.2025 from https://www.degruyterbrill.com/document/doi/10.1515/itit-2016-0039/html
Scroll to top button

[8]ページ先頭

©2009-2025 Movatter.jp