[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [cobalt-users] Problem with STDIN, in CGI
- Subject: RE: [cobalt-users] Problem with STDIN, in CGI
- From: "Dan" <dan@xxxxxxxxxxxxx>
- Date: Wed May 3 17:42:10 2000
>
> >>INPUT TYPE="hidden" NAME="recipient" VALUE="cmoreno@xxxxxxxxxxxxx">
>
> Umm, you realize this open you up to becoming a spam source ;0
>
> Anyone can change a form value and send it back to the server...
>
>
Usually the script only allows sending from specific domains or IP's. While
it could be faked, it's a lot easier to find a *.kr open relay.
--
Dan Kriwitsky