Nigel Allen wrote:

> The required file name format is:

> "Mail_"

> StrataNumber

> "_11-Email_"

> Email Subject (max 64 characters)

> ".eml"

You want to be careful.  What if I make the email subject:

Subject: ../../../../Hello_World

You need to sanitize the Subject to remove potentially-dangerous characters.
Dumping files into /tmp and giving an attacker substantial control over
the filename is a recipe for trouble.

I'll leave it to others to help you out with your Perl. :)

Regards,

David.
_______________________________________________
NOTE: If there is a disclaimer or other legal boilerplate in the above
message, it is NULL AND VOID.  You may ignore it.

Visit http://www.mimedefang.org and http://www.roaringpenguin.com
MIMEDefang mailing list MIMEDefang@lists.roaringpenguin.com
http://lists.roaringpenguin.com/mailman/listinfo/mimedefang

Reply via email to