From: David Fayram Date: 2003-07-29T04:26:54+09:00 Subject: Re: smtp.sendmail security I'm surprised that Net::STMP lets you do that. It really should be set up so when taint checking is on, it won't let you do that. Suffice to say that is very bad. You shouldn't allow that to happen. Anyone could change the cgi params on any page. Unless this data is in a server-stored session, this means you've basically got a web-gateway open relay. Great for enterprising spammers and kiddies. In general, treat CGI form data as unsanitay biowaste :) I'm not sure about mailing multiple people and whatnot, but one person is enough. - Dave Fayram kirindave@lensmen.net Idealist / Developer ---------- Original Message ---------------------------------- From: "John W. Long" Reply-To: ruby-talk@ruby-lang.org Date: Tue, 29 Jul 2003 04:20:12 +0900 >We are using the following code to send email messages from an online form >on our web site: > > Net::SMTP.start('localhost', 25) {|smtp| > smtp.sendmail(message, @from, @to) > } > >The values of @from and @to are taken directly from their cgi.params values >with basically no modification. Is it possible for someone to exploite this >as a security vulnerability? Could someone use it to send email to multiple >addresses? > >-- >John Long >http://www.wiseheartdesign.com > > > ____________________________________________________________ Free 20MB Web Site Hosting and Personalized E-mail Service! Get It Now At Doteasy.com http://www.doteasy.com/et/