On Wed, Feb 12, 2003 at 04:30:14PM -0700, Jason R. Mastaler wrote:
>A possible "hole" exists when someone finds one of your messages, and
>sends you a new message with those same headers, but a different
>body. It will get delivered since the fingerprint verification will
>succeed. 

Perhaps another way to deal with this is to have the fingerprint checking
code ignore all whitespace at the end of the body.  Both when generating
the fingerprint and when checking it.  

While this might solve the problem that I was seeing, I've still seen
lots of MTA's that completely mangle the messages that go through them.
I don't see any easy way to solve this.  So I'm avoiding using "body" in
the fingerprint.
_________________________________________________
tmda-workers mailing list ([EMAIL PROTECTED])
http://tmda.net/lists/listinfo/tmda-workers

Reply via email to