is MAIL safe ?
| From: | shaun | Date: | Tue, 14 Dec 2004 21:49:03 +0000 |
| Subject: | is MAIL safe ? | ||
| Groups: | php.pear.general | ||
| Request: | Send a blank email to pear-general+get-16244@lists.php.net to get a copy of this message | ||
Hello,
I am having users fill out a PDF form with information, having PDF form
send FDF data to script on a web sever. Script (see below) takes data
file, saves to disk, attaches to email, sends email and then deletes
data file from server. All works perfectly.
The question: Somebody hacked the server, changing the default.htm pages
of each website (domain) to have some spanish political message. The
server people are point the blame at me and the PEAR MAIL stuff. This is
possible, have I opened the door ? Have looked around for security PEAR
MAIL information, but not found any. Surely having the PEAR included
with the PHP install points to the fact it is not a risk ?
Any information would help me to understand,
Thanks
Shaun
<?php
$tmpfname = tempnam("/tmp", "tmp_");
$tmpfname .= ".fdf";
$fptr = fopen("$tmpfname", "w");
fputs($fptr, $HTTP_RAW_POST_DATA);
fclose($fptr);
?>
<?php
include('Mail.php');
include('Mail/mime.php');
$text = '1. Double click the attachment 2. Print the form';
$html = '<html><body><p align="center">1. Double click the
attachment2.
Print the form</p></body></html>';
$file = $tmpname;
$crlf = "\r\n";
$hdrs = array(
'From' => 'test@testr.info',
'Subject' => 'Form'
);
$mime = new Mail_mime($crlf);
$mime->setTXTBody($text);
$mime->setHTMLBody($html);
$mime->addAttachment($file, 'text/plain');
$body = $mime->get();
$hdrs = $mime->headers($hdrs);
$mail =& Mail::factory('mail');
$mail->send('test@test.org', $hdrs, $body);
unlink($tmpfname);
?>