Full Disclosure mailing list archives

Re: Re: [MailServer Notification]To recipient: Message matched eManager setting and action was taken.


From: Valdis.Kletnieks () vt edu
Date: Thu, 29 Dec 2005 05:36:36 -0500

On Wed, 28 Dec 2005 15:24:02 EST, Michael Holstein said:
Rule/Policy: Sexual Discrimination

Ha .. so not only do they have a misconfigured copy of Trend eMail 
scanner (eg: bounce to list) .. they try to flag on "sexual 
discrimination" words.

Probably one of the flamers calling another flamer a "homo" or some such.

I've found that calling somebody a "fucking idiot" won't trigger most of those
scanners, but saying that something is "a real bitch to configure correctly"
will.  Go figure. ;)

ObSecurity:  What ways can you think of to abuse this?  Use it as a DDoS
vector by forging the From: to bounce to?  Creative ways of excluding one
recipient of an e-mail discussion?  Other novel uses? ;)

Attachment: _bin
Description:

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: