Re: Exploit this for fun and, well, fun. (LONG)

by Mr.T
in reply to Exploit this for fun and, well, fun. (LONG)

I have a question for you:
Why do you feel like bringing up scripts from MSA? It's an old place, and I hope that no one is really still using scripts from there... it's kind of like opening a closet of skeletons... there is no point! :)

Maybe it should just be left as it is, because you and all of us already know that it is old, and not secure enough to use in today's internet world of Perl >=

I was just wondering, because perhaps you already knew that this was not the best question in the world, since you said that you were prepared for major downvotes :).

Just my opinion.

(ichimunki) re x 2: Exploit this ...
by ichimunki
    MSA is one of the most widely used Perl scripts I know of. If you go shopping for a web host you will frequently see them offering as a way for HTML-only coders to enable their otherwise non-CGI sites to generate email -- this is the only way someone with a non-dynamic site can get feedback.

    The script archive is not "an old place", it is current. In fact was just updated to patch a security hole less than ten days ago. The simple truth is that this script is in widespread use and a discussion of it is very relevant. We have even had some newer Monks on PM asking about it.

    Finally, it is a popular mantra here at PM to deride the use of some have said that it is insecure, others have said it opens the servers to being "owned". I looked at the script. I saw no such danger with the latest version. And the major security concern with the previous version allowed anyone to use to send email from a server they weren't authorized to use. While I find that to be an important flaw, it is not critical. There is a big difference between an open relay and an "owned" machine.

    My conclusion was that the script is acceptable-- I made my post to make sure I had all the facts (and I think I've gotten enough of them to reach my conclusion). It just wouldn't be my choice of script to use-- but I can code Perl and make my own script tailored to my exact needs. I have no reason to rely on this since I don't write HTML anymore, I write CGIs and let them do that for me. For those who don't code Perl, I am not going to worry if they want to use this script (the current version).
      Wow, sorry for making it sound like I thought I knew what I was talking about! :) I didn't know that MSA is current, I always just thought it was an archive of sorts. Thanks for clearing that up for me! :)

      qw/"I pity da foo' who don't use Perl!"/;

