Hey Sam - are you implying he should add teh capability and default for a
"MAX_DOT_DEPTH" or something similar to prevent this?

And assuming he does, are you willing to include? Then he knows whether or
not to bother fixing - personally it's not something I can see myself having
a use for, but I wasn't sure how to take your answer...

m/

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of Sam
Varshavchik
Sent: Friday, November 21, 2003 3:17 PM
To: Courier
Subject: [courier-users] Re: Wildcard DNS + Courier? (fix patch
included)


Jeff Potter writes:

> This change allows for users to add ".domain.com" entries in the
> hosteddomains file. Given a hostname "some.funky.domain.com", this
> patch adds checks for ".funky.domain.com", ".domain.com", and ".com",
> in that order.  Are you willing to add this into the main branch?

There's a problem with this approach.  Someone specifying a recipient
address of "[EMAIL PROTECTED]", with
sufficient intensity, can cause a DDOS attack.  Although DB lookups are
relatively fast, this is still something that cannot be ignored.




-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
Does SourceForge.net help you be more productive?  Does it
help you create better code?  SHARE THE LOVE, and help us help
YOU!  Click Here: http://sourceforge.net/donate/
_______________________________________________
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users

Reply via email to