diff options
| author | Danilo M. <danix@danix.xyz> | 2026-09-08 13:29:30 +0200 |
|---|---|---|
| committer | Danilo M. <danix@danix.xyz> | 2026-09-08 13:29:30 +0200 |
| commit | 5caedfb5068683ef793a338fae30f8269f9f865d (patch) | |
| tree | 98aa89ac9740844a3a3fd9caa0c8ac4f40a7235c /.gitignore | |
| parent | e497d06483baea7cb6288cf52ff4c897bf1f00fd (diff) | |
| download | abusectl-5caedfb5068683ef793a338fae30f8269f9f865d.tar.gz abusectl-5caedfb5068683ef793a338fae30f8269f9f865d.zip | |
test: fixtures for the parser, documentation ranges only
Four hand-written messages using example.org, example.invalid and the
RFC 5737 documentation IP ranges. No real phishing sample goes in this
repository: it would carry the recipient identifiers this tool exists to
keep out of reports, and a repository is potentially public.
forged-chain.eml is the one that matters. The attacker prepends two
Received headers naming an innocent third party, so a parser that walks
past the trust boundary reports 198.51.100.7 rather than 203.0.113.99.
Weekdays verified with date(1) rather than written from memory, since an
RFC2822 parser validates the day against the date and a wrong one is
indistinguishable from a malformed header.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KphFXTc2QajxXsHWyvGJ4R
Diffstat (limited to '.gitignore')
0 files changed, 0 insertions, 0 deletions
