[SAtalk] FormMail.pl spam

2003-01-14 Thread Ed Weinberg
I am surprised that SA does not recognize spam sent by FormMail.pl. Back around 1987 a 15 year old kid named Matt Wright wrote a FormMail script. The original insecure version is still in use on a million sites (no exageration). Spammers figured out how to send email through it. Each stock scrip

Re: [SAtalk] FormMail.pl spam

2003-01-14 Thread Jack L. Stone
At 11:53 AM 1.14.2003 -0500, Ed Weinberg wrote: >I am surprised that SA does not recognize spam sent by FormMail.pl. >Back around 1987 a 15 year old kid named Matt Wright wrote a FormMail >script. The original insecure version is still in use on a million >sites (no exageration). Spammers figured

Re: [SAtalk] FormMail.pl spam

2003-01-14 Thread Maxime Ritter
On Tue, Jan 14, 2003 at 11:53:23AM -0500, Ed Weinberg wrote: > I am surprised that SA does not recognize spam sent by FormMail.pl. > =START EXAMPLE== > Below is the result of your feedback form. It was submitted by > [EMAIL PROTECTED] ([EMAIL PROTECT

Re: [SAtalk] FormMail.pl spam

2003-01-14 Thread Rich Puhek
Ed Weinberg wrote: I am surprised that SA does not recognize spam sent by FormMail.pl. Back around 1987 a 15 year old kid named Matt Wright wrote a FormMail script. The original insecure version is still in use on a million sites (no exageration). Spammers figured out how to send email through

Re: [SAtalk] FormMail.pl spam

2003-01-14 Thread Theo Van Dinter
On Tue, Jan 14, 2003 at 11:53:23AM -0500, Ed Weinberg wrote: > I am surprised that SA does not recognize spam sent by FormMail.pl. BUGGY_CGI catches those. -- Randomly Generated Tagline: I'm paranoid, that's why everyone hates me... msg12155/pgp0.pgp Description: PGP signature

RE: [SAtalk] FormMail.pl spam

2003-01-14 Thread Michael Moncur
Ed Weinberg wrote: > I am surprised that SA does not recognize spam sent by FormMail.pl. The BUGGY_CGI rule catches that, it's been in SA for a long time. It must work (in conjunction with other rules) because I haven't had a formmail spam slip through in at least 6 months. -- Michael Moncur mg

RE: [SAtalk] FormMail.pl spam

2003-01-14 Thread Steve Thomas
| Back around 1987 a 15 year old kid named Matt Wright wrote a FormMail | script. The original insecure version is still in use on a million | sites (no exageration). Spammers figured out how to send email through | it. I wrote my own formmail.pl script which e-mails the spammer and the abuse@ a

Re: [SAtalk] FormMail.pl spam

2003-01-14 Thread Justin Mason
Ed Weinberg said: > I am surprised that SA does not recognize spam sent by FormMail.pl. > Back around 1987 a 15 year old kid named Matt Wright wrote a FormMail > script. The original insecure version is still in use on a million > sites (no exageration). Spammers figured out how to send email th

Re: [SAtalk] FormMail.pl spam

2003-01-14 Thread Justin Mason
Jack L. Stone said: > Ed, your info about Formmail is not correct and is very stale. In fact > there are more than 2 Million users and the security hole was patched. That > doesn't mean that some have not kept up to date and don't know about the > breach of security caused by using the older versi

Re: [SAtalk] FormMail.pl spam

2003-01-14 Thread Jack L. Stone
At 06:30 PM 1.14.2003 +, Justin Mason wrote: > >Jack L. Stone said: >> Ed, your info about Formmail is not correct and is very stale. In fact >> there are more than 2 Million users and the security hole was patched. That >> doesn't mean that some have not kept up to date and don't know about th