Re: is MAIL safe ?

From: Date: Wed, 15 Dec 2004 14:04:34 +0000
Subject: Re: is MAIL safe ?
References: 1  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-16257@lists.php.net to get a copy of this message
* Shaun <shaun@crapdesign.co.uk>: > I am having users fill out a PDF form with information, having PDF form > send FDF data to script on a web sever. Script (see below) takes data > file, saves to disk, attaches to email, sends email and then deletes > data file from server. All works perfectly. > > The question: Somebody hacked the server, changing the default.htm pages > of each website (domain) to have some spanish political message. The > server people are point the blame at me and the PEAR MAIL stuff. This is > possible, have I opened the door ? Have looked around for security PEAR > MAIL information, but not found any. Surely having the PEAR included > with the PHP install points to the fact it is not a risk ? The only thing I can think of off the top of my head has to do with how you're sending your mail. If you were using SMTP -- and it does not look like this is the case from your example -- and needed to provide auth information to the SMTP server, theoretically a hacker could have been listening to SMTP traffic, snooped the user and password, and then used that to gain access to, well, possibly the machine on which the mail server resides. The only other security issue with Mail has nothing to do with the module itself so much as programming practices -- you don't want to send to just anybody as anybody. Again, from your example, it doesn't look like you're doing anything wrong in this regard. My suggestion: ask the "server people" why they suspect PEAR::Mail, and try and get something other than speculation from them. -- Matthew Weier O'Phinney | mailto:matthew@garden.org Webmaster and IT Specialist | http://www.garden.org National Gardening Association | http://www.kidsgardening.com 802-863-5251 x156 | http://nationalgardenmonth.org

« previous php.pear.general (#16257) next »