[EMAIL PROTECTED] (Bob W.) wrote in
<[EMAIL PROTECTED]>:
>In article <9c7h7r$op$[EMAIL PROTECTED]>, "SpamCop"
><[EMAIL PROTECTED]> wrote:
>
>> I have what appears to me to be a spammer using MY formmail.cgi script
>> to send spam out of my server today... here are a couple entries from
>> my log file.
>
><snip>
>
>> I have since removed the cgi script so this can't happen at the
>> moment. Can
>> someone tell me where exactly these are coming from and what web pages
>> they
>> are referring to? Do you think the IP address is bogus? Any other
>> helpful
>> suggestions appreciated!
>
>If possible, secure the CGI to stop others from using it. IIRC, you can
>user the REFERER environment variable for that... I think.
Easy to spoof any environment variables. Do not rely on any user input, or
any input provided by the user's browser, as security measures for a CGI.
>To make it bulet-proof, recode it so that it doesn't accept any
>recipient address variables passed to it; just hardcode the recipient
>address into the CGI itself.
Well, I don't know about bullet-proof. One would have to examine the full
code. There could be other weaknesses in the code that are susceptible to
exploits. However, hardcoding the recipients is a good way to make the
script more secure.
>If there are various addresses that need to accept email via the CGI,
>you could create a database of authorized recipient addresses and
>associate each with an encoded key; pass the key to the CGI, the CGI
>queries the database, and the proper recipient will get the mail.
--
Sheila King
http://www.thinkspot.net/sheila/
http://www.k12groups.org/
_______________________________________________
SpamCop-Help mailing list
[EMAIL PROTECTED]
http://news.spamcop.net/mailman/listinfo/spamcop-help