From: Akinori MUSHA Date: 2001-12-30T01:09:58+09:00 Subject: [ruby-dev:15602] Net::FTP: ftp anonymous password (PR#223)  メールがエラーで弾かれるそうなので、転送します。 At Sat, 29 Dec 2001 16:03:23 +0000, eperez@dei.inf.uc3m.es wrote: > From: eperez@dei.inf.uc3m.es > Date: Sun, 30 Dec 2001 00:48:31 +0900 (JST) > Subject: Net::FTP: ftp anonymous password (PR#223) > To: bugs-admin@ruby-lang.org > Cc: ruby-bugs@ruby-lang.org > Message-Id: <20011229154831.2F8A11EE@helium.ruby-lang.org> > > > --ZPt4rx8FFjLCG7dd > Content-Type: text/plain; charset=us-ascii > Content-Disposition: inline > > I've seen that Net::FTP sends the user name when doing ANONYMOUS ftp gets. > I see a lot of problems: > - Sending the user name if the user doesn't know that it's sent doesn't protect the user state of ANONYMOUS > - Spyware is not a good idea, most users don't like it. > - Sending the user name helps SPAM instead of stopping it. Many ftp sites use this information to send you unsolicited email. > - Sending the user name doesn't help ftp sites to know who the cracker is, crackers are not stupid to send their email address. > - Sending the user name can be used to discriminate the user. > > By all of these reasons I argue that Net::FTP to don't > send the user email by default. > > Some time ago two very important ftp clients wget and > lftp stopped sending the user name as password based on > my input. > > As more and more ftp clients are moving to this > anonymous@ password (for example the kde kio ftp, qt3, > gnome-xml, perl's Net::FTP, python's ftplib.py) > I recommend you to apply the patch. > > I send you the bugfix. > > --ZPt4rx8FFjLCG7dd > Content-Type: text/plain; charset=us-ascii > Content-Disposition: attachment; filename="ruby1.6-netftp-nospam.diff" > > --- ruby/1.6/net/ftp.rb.orig Wed Dec 26 13:54:34 2001 > +++ ruby/1.6/net/ftp.rb Sat Dec 29 10:56:33 2001 > @@ -215,25 +215,16 @@ > end > private :transfercmd > > - def getaddress > - thishost = Socket.gethostname > - if not thishost.index(".") > - thishost = Socket.gethostbyname(thishost)[0] > - end > - if ENV.has_key?("LOGNAME") > - realuser = ENV["LOGNAME"] > - elsif ENV.has_key?("USER") > - realuser = ENV["USER"] > - else > - realuser = "anonymous" > - end > - return realuser + "@" + thishost > - end > - private :getaddress > - > def login(user = "anonymous", passwd = nil, acct = nil) > if user == "anonymous" and passwd == nil > - passwd = getaddress > + # If there is no anonymous ftp password specified > + # then we'll just use anonymous@ > + # We don't send any other thing because: > + # - We want to remain anonymous > + # - We want to stop SPAM > + # - We don't want to let ftp sites to discriminate by the user, > + # host or country. > + passwd = "anonymous@" > end > > resp = "" > > --ZPt4rx8FFjLCG7dd-- -- / /__ __ Akinori.org / MUSHA.org / ) ) ) ) / FreeBSD.org / Ruby-lang.org Akinori MUSHA aka / (_ / ( (__( @ iDaemons.org / and.or.jp "Somewhere out of a memory.. of lighted streets on quiet nights.."