Re: Help Needed with Perl cgi script and spam problem



axel@xxxxxxxxxxxxxxxxxxxxxx wrote:
>>> AFAIK the most typical problem is lack of sufficiently paranoid checks
of parameters entered into forms before passing them to sendmail e.g.
your script sends using "sendmail -t" (take recipeint addresses from
to:/cc: headers) and abusers use some other entries (e.g. *multiline*
subject) to insert "extra" to:/cc: headers.
I'm pretty sure that is how it was done but I really need to know exactly how to do it so I can fix the code to prevent it.

How on earth do you expect people to tell you *exactly* how to fix
an unseen script and without having access to the details of the
spam generated?

Axel

Well Axel, if you had really read my post, I wasn't asking for somebody to fix it but asking how they are attacked so I could fix it.

--

Knute Johnson
email s/nospam/knute/
.



Relevant Pages

  • Re: Help Needed with Perl cgi script and spam problem
    ... of parameters entered into forms before passing them to sendmail e.g. ... your script sends using "sendmail -t" (take recipeint addresses from ... How on earth do you expect people to tell you *exactly* how to fix ...
    (comp.lang.perl)
  • lk-changelog.pl 0.167
    ... This script is used by Linus and Marcelo to rearrange and reformat BK ... fix obfuscation of unknown addresses in terse/oneline modes ... Bryan O'Sullivan's address got hosed. ... $indent is auto-generated from $indent1. ...
    (Linux-Kernel)
  • Re: Problem with popen on windows
    ... I just found a fix that works for me.. ... parent for the child script.. ... Private Function ParseCmdLine ... >> def system ...
    (comp.lang.ruby)
  • Re: Script-in SELF Permission?
    ... Im all set in the mailbox rights area, ... Using the script Quest gave me to fix the msExchangeSecurityDescriptor ... I need a script or app that will go into each user object ...
    (microsoft.public.windows.server.active_directory)
  • Re: Add/Removed page problem
    ... This script lists all the negative icon references present in the registry, ... Download http://windowsxp.mvps.org/utils/ARPNegCheck.vbs ... That is the 'fix' that doesn't work or apply, ... TIA, Dick ...
    (microsoft.public.windowsxp.help_and_support)