From: Hugh Sasse Staff Elec Eng Date: 2003-08-26T19:04:09+09:00 Subject: Re: Email and smtp.sendmail security vulnerabilities? On Tue, 26 Aug 2003, John W. Long wrote: > Hi, > > I've created a small class and supporting methods for sending email from a > web page. I use it like this: > > msg = Web::Email::Message.new( > :from => from, > :to => to, > :subject => subject, > :body => body.untaint # security vulnerability? > ) > Web::Email.send(msg) > > All of the email strings (:from, :to, etc...) could potentially come from > the the outside world. I'm doing some munging on the :from, :to, and That is your security problem in itself. Far better would be to permit certain addresses only, and let the user choose them by passing a hash (such as MD5) of the desired address into the form. Thus different addresses cannot easily be created, because only those selected addresses will be reverse mapped (md5->address). This selection would obviously have to be done from a radio button or similar selector. Why go to all this trouble? See http://spamcop.net/fom-serve/cache/270.html for links to details about formmail which used to be open. Basically, anyone could use your script for relaying mail via your machine... Hugh