You are here: Re: mail() injection, am i safe? « PHP Programming Language « IT news, forums, messages
Re: mail() injection, am i safe?

Posted by juglesh on 11/14/05 20:07

Simon wrote:
> "Toby Inkster" <usenet200511@tobyinkster.co.uk> wrote in message
> news:40uf43-gsl.ln1@ophelia.g5n.co.uk...
> > Simon wrote:
> >
> >> My question would be more, what can they inject in the actual body of the
> >> email?
> >
> > Make sure the "additional headers" parameter ends with "\r\n\r\n" and you
> > ought to be fine.
> >
>
> Sorry, I am still not sure I follow,
> Almost everything is hard coded, (the 'to' and the 'subject').
>
> and the header is
>
> "Reply-To: webmaster@example.com."\n" .
> "From: webmaster@example.com."\n" .
> "Return-Path: webmaster@example.com."\n" .
> "MIME-Version: 1.0\n".
> "Content-type: text/plain; charset=iso-8859-1\n".
> "Content-transfer-encoding: 8bit\n".
> "Date: " . date('r', time()) . "\n".
> "X-Priority: 3\n".
> "X-MSMail-Priority: Normal\n".
> "X-Mailer: PHP/" . phpversion();

next comes the $message. if the message was
\n bcc: unlucky1@recipient.com, unlucky2@adslfkj.com, \n
lemme tell ya bout these blue pills...

(or something like that)
You can see where that aint gonna be too cool.

> So are you saying I should add "\r\n\r\n" as well?

that's supposed to make the mailing program quit with the headers and
send the rest as the message.

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация