Bugtraq mailing list archives
Re: Spammers can hide behind 'Email a friend/article' scripts.
From: matthias () astrum ch
Date: Tue, 27 Apr 2004 08:15:20 +0200 (CEST)
# Description: Spammers can hide behind 'Email a friend/article' scripts.
These are just an instance of the more general form hijacking attacks. I've seen several attempts to abuse feedback forms and similar through a simple scheme - each form field was filled with "To: <someaddr>\nFrom: <someaddr>\n" Form scripts that do not check for newlines within the fields are vulnerable to those attacks in general, for example in perl pseudocode: open(SENDMAIL, "|/usr/sbin/sendmail -someflags") or print "Some Error: $!\n"; print SENDMAIL "From: $formfield_from\n"; print SENDMAIL "To: $recipient-taken-from-some-config\n"; print SENDMAIL "Subject: Foo Bar '$formfield_subject'\n"; print SENDMAIL "\nMail content\n"; close(SENDMAIL); If $formfield_subject contains the above line with additional To:s, it depends on the MTA whether he parses the additional headers and sends them along. Around end of march/beginning of april 2004 I've seen a number of attempts to abuse such scripts. It look like a systematic approach and not some random guesses. -- Matthias -- Matthias' Braindump http://matthias.leisi.net/
Current thread:
- Spammers can hide behind 'Email a friend/article' scripts. cyber_flash (Apr 26)
- Re: Spammers can hide behind 'Email a friend/article' scripts. matthias (Apr 27)
- Re: Spammers can hide behind 'Email a friend/article' scripts. 3APA3A (Apr 27)