[EMAIL PROTECTED] (Bob W.) wrote in
<[EMAIL PROTECTED]>: 

>In article <9c7h7r$op$[EMAIL PROTECTED]>, "SpamCop" 
><[EMAIL PROTECTED]> wrote:
>
>> I have what appears to me to be a spammer using MY formmail.cgi script
>> to send spam out of my server today... here are a couple entries from
>> my log file.
>
><snip>
>
>> I have since removed the cgi script so this can't happen at the
>> moment.  Can
>> someone tell me where exactly these are coming from and what web pages
>> they
>> are referring to?  Do you think the IP address is bogus? Any other 
>> helpful
>> suggestions appreciated!
>
>If possible, secure the CGI to stop others from using it. IIRC, you can 
>user the REFERER environment variable for that... I think.

Easy to spoof any environment variables. Do not rely on any user input, or 
any input provided by the user's browser, as security measures for a CGI.

>To make it bulet-proof, recode it so that it doesn't accept any 
>recipient address variables passed to it; just hardcode the recipient 
>address into the CGI itself.

Well, I don't know about bullet-proof. One would have to examine the full 
code. There could be other weaknesses in the code that are susceptible to 
exploits. However, hardcoding the recipients is a good way to make the 
script more secure.

>If there are various addresses that need to accept email via the CGI, 
>you could create a database of authorized recipient addresses and 
>associate each with an encoded key; pass the key to the CGI, the CGI 
>queries the database, and the proper recipient will get the mail.



-- 
Sheila King
http://www.thinkspot.net/sheila/
http://www.k12groups.org/

_______________________________________________
SpamCop-Help mailing list
[EMAIL PROTECTED]
http://news.spamcop.net/mailman/listinfo/spamcop-help

Reply via email to