in reply to Vetting a CGI script
For arbitrary input, consider that you are offering to set up a spam relay:
$in{myName} = "\n.\nMAIL FROM fake@dev.null\n" . "RCPT TO poor@target.domain\n" . "DATA\n$spam_message_goes_here\n\.\n" . "MAIL FROM junk@throwaway\nRCPT TO nobody@nowhere\n" . "DATA\n\nJust junk to avoid throwing an error"
... or anything else someone might want to do with access to your SMTP server. (Moral of story: Net::SMTP ... but I assume you are doing this as justification for a rewrite anyway.)
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Vetting a CGI script
by dvergin (Monsignor) on Nov 12, 2003 at 18:09 UTC | |
by idsfa (Vicar) on Nov 12, 2003 at 18:23 UTC | |
by dvergin (Monsignor) on Nov 12, 2003 at 18:49 UTC | |
|
Re: Re: Vetting a CGI script
by iburrell (Chaplain) on Nov 13, 2003 at 00:05 UTC |