good chemistry is complicated, and a little bit messy -LW |
|
PerlMonks |
Re: Re: Vetting a CGI scriptby iburrell (Chaplain) |
on Nov 13, 2003 at 00:05 UTC ( [id://306684]=note: print w/replies, xml ) | Need Help?? |
That attack isn't a problem unless he was talking directly to the receiving mail server over SMTP. sendmail will encode the period and unless the receiving mail server is completely broken, the message will just have some SMTP commands in it.
Update: I forgot about the -i flag to sendmail to prevent the rogue period from ending the message. The SMTP commands shouldn't be interpreted by sendmail but the period can be used to shorten the message sent.
In Section
Seekers of Perl Wisdom
|
|