Re: Sendmail User ID

From: Date: Thu, 18 Jan 2001 21:38:40 +0000
Subject: Re: Sendmail User ID
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-35453@lists.php.net to get a copy of this message
On Thu, 18 Jan 2001 13:50:56 -0500, Yurais Fernández Leal <yurais@medired.scu.sld.cu> wrote: >The problem is, yes, I know that in the remote mail client the mail >appears as if sent from me@mydomain.com, but in the sendmail >connection, for example the Return-Path is set to the UID of the web >server, the problem This issue was discussed a few days ago in another thread. The site performing final delivery determines Return-Path from the envelope address. That means you cannot control Return-Path by means of header manipulation. The only way to control the envelope address is to have the web server call sendmail with the -f option as a trusted user. The -f option will let you specify any address. This has great potential for abuse, so you must tell sendmail, via its configuration, that the web server UID can be trusted. But before doing that, consider the potential for abuse. For example, in a virtual hosting environment, what would prevent PHP authors from providing users with a web form which takes an email address input and calls sendmail with the -f option, forcing it to use a possibly forced address as the envelope address? If the web server is a trusted sendmail user, any PHP script could do that. Whoa! Egan

« previous php.general (#35453) next »