Re: RE: Bug #2203 Updated: Failed mail() function untrackable.
| From: | Rasmus Lerdorf | Date: | Thu, 01 Jan 1970 00:00:00 +0000 |
| Subject: | Re: RE: Bug #2203 Updated: Failed mail() function untrackable. | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-12334@lists.php.net to get a copy of this message | ||
> This fix still doesn't prevent people from misusing the mail() function,
> however. I can ask people to use my script instead, but as long as I'm
> allowing them to use PHP on their own hosted sites, this implies that they
> are also allowed to use mail(), and that means they're capable of messing it
> up and inadvertently spamming my inbox. An option in php.ini to either turn
> some form of tracking/taglining on or off, or alternately disable the
> function, or limit its use would be a Good Thing(TM) IMHO...
Just set the sendmail_path php3.ini entry to something like /bin/false and
the function won't work. This wouldn't stop someone from calling popen()
directly, or even doing an exec("mail") call. You would have to turn on
safe-mode to block these as well.
-Rasmus