Gossamer Forum
Home : General : Perl Programming :

Anti-Spam fix for formmail.pl

Quote Reply
Anti-Spam fix for formmail.pl
Important news for webmasters !

Widely used FormMail.pl Web-to-Email CGI Script Allows Unauthorized Users to Send Mail (e.g., spam) Anonymously. - March 16, 2001
For a full description see
http://securitytracker.com/alerts/2001/Mar/1001108.html

A patched version of the perl script is available at
http://www.mailvalley.com/formmail/
The patched version of the script
1)Allows you to specify a list of recipients in a text file, who are authorized to receive emails. So the script will only send mail to addresses listed in this file thus protecting against the spam exploit.
2) Prevents unauthorised users from fetching your server's environment variables through the formmail script.

Quote Reply
Re: Anti-Spam fix for formmail.pl In reply to
Yeah, and? There is virtually no way to stop people from entering dud info. How would you expect the script to know that the user doesn't really have an email address called bill.gates@microsoft.com????

Andy

webmaster@ace-installer.com
http://www.ace-installer.com
Quote Reply
Re: Anti-Spam fix for formmail.pl In reply to
Thats not what he's saying Andy. He's talking about SPAM

Installs:http://wiredon.net/gt
FAQ:http://www.perlmad.com

Quote Reply
Re: Anti-Spam fix for formmail.pl In reply to
Oh yeah Blush Whoops!

Andy

webmaster@ace-installer.com
http://www.ace-installer.com