Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: Vulnerability in websendmail

Re: Vulnerability in websendmail

From: Randal Schwartz <merlyn_at_STONEHENGE.COM>
Date: Tue, 8 Jul 1997 07:11:27 -0700

>>>>> "Razvan" == Razvan Dragomirescu <drazvan_at_kappa.ro> writes:

Razvan> As many other cgi-bin programs, this one does not check for special
Razvan> characters in the user input.

Razvan> Here's what it does:
Razvan> (...)
Razvan> $cmd="| $MAILBIN $VAR_receiver";
Razvan> open (PIPEOUT, $cmd);

It really amazes me how many newbie Perl hackers:
(1) ignore the CGI Security FAQ (especially the parts about perl), or
(2) roll their own mail sending stuff, instead of using Net::SMTP
    or the more powerful Mail::Tools package, both found in the CPAN.

On second thought, maybe it's not amazing. :-)

--
Name: Randal L. Schwartz / Stonehenge Consulting Services (503)777-0095
Keywords: Perl training, UNIX[tm] consulting, video production, skiing, flying
Email: <merlyn_at_stonehenge.com> Snail: (Call) PGP-Key: (finger merlyn_at_ora.com)
Web: My Home Page!
Quote: "I'm telling you, if I could have five lines in my .sig, I would!" -- me
Received on Jul 08 1997
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]