You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@httpd.apache.org by Bill -Sx- Jones <sn...@mac.com> on 2002/03/12 14:16:44 UTC

One more rant ...

OK, just one small rant about security and I will go away again...

Attn Apache Admin newbies -

Run this thru your brain, see if it can cover the vast distance between your
ears - hopefully passing other thoughts along the way...  :)

Back in 1997 someone in Australia asked me to write him a Perl script to
allow him to read a file and redirect URLs based upon the key URL in a file.
I said no problem, I charged him $50 bucks - today we can do that without
Perl and we have a ton of crappy adult sites with bunches and bunches of
redirecting going on to prove it ...

Back in 2001 a student kept pestering me to explain how a simple HTML
oriented email could be used to repeatedly send them spam - her argument was
if she simply deleted the e-mail then how could the spammers know her
address was valid - I said just use a single serialized GIF in the email and
the remote server would log it - then the remote spammer would know your
serial number was a valid e-mail address.

So, just because you cannot do something ...
1) Doesn't mean that it is impossible, and
2) Doesn't mean it's a cool thing to do...

Enjoy!
-Sx-  :]

PS - If anyone wants to beat me up over this - you can find me on a UT
server near you (code name IUDICIUM.)

PPS - http://www.cpan.org/authors/id/S/SN/SNEEX/HTML_Mailer-v0.01A


---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org