aboutsummaryrefslogtreecommitdiffstats
path: root/docs/specs/2026-09-09-report.md
diff options
context:
space:
mode:
authorDanilo M. <danix@danix.xyz>2026-09-10 11:23:27 +0200
committerDanilo M. <danix@danix.xyz>2026-09-10 11:23:27 +0200
commit2611c6485fa733e627f2c62c0369260f3a96d0bc (patch)
treeb4d55c13042d40d50146854ea82689245b1882e0 /docs/specs/2026-09-09-report.md
parentf2fea43813ccebb1cf60e8afa5d4c7cdc52d0a20 (diff)
downloadabusectl-2611c6485fa733e627f2c62c0369260f3a96d0bc.tar.gz
abusectl-2611c6485fa733e627f2c62c0369260f3a96d0bc.zip
docs: record the report spec and both sweeps
Sweep A over 92 real messages after task 1 changed parse.py: 1685 indicators, 92 bodies, 0 crashes, 0 empty parses, no address from a raw source in the IOC output and no recipient address in any generated body. What it measured is the limit the spec already accepts. Subject is published verbatim, and 14 of the 92 messages carried the recipient's local part inside it because the kit personalises the lure. None carried it in the From display name, and the envelope recipient was cut from the boundary Received line in every message. That is the whitelist governing which headers travel rather than what is inside one, which the spec's "attacker-controlled free text is published unfiltered" section states outright and names the sweep as the cover for. personalised-subject.eml pins all three behaviours, the accepted one included, so the number cannot drift unnoticed. The for-clause test is mutation-checked: stop cutting the clause and all three fail. Sweep B, 12 hand-picked public targets and none from the corpus: 12 of 12, 0 failures, all five RIRs parseable, IPv6 live, the label walk and the multi-part suffix both correct. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LByBnw83xr9YP85nskzkyE
Diffstat (limited to 'docs/specs/2026-09-09-report.md')
0 files changed, 0 insertions, 0 deletions