Great Circle Associates Majordomo-Workers
(October 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Is 'wh*ch' useful? --> moved from -work
From: Dave Wolfe <dwolfe @ risc . sps . mot . com>
Date: Thu, 16 Oct 1997 08:50:19 -0500 (CDT)
To: mrauterkus @ sportsurf . net (Mark Rauterkus)
Cc: majordomo-workers @ greatcircle . com (Majordomo developer's mailing list)
In-reply-to: <199710160250.UAA15315@sportsurf.net> from "Mark Rauterkus" at Oct 15, 97 11:00:26 pm
Reply-to: Dave Wolfe <david_wolfe @ risc . sps . mot . com>

[ Mark Rauterkus writes: ]
> 
> Not sure what [...] David, mean with the following.
> 
> RE: Majorcool.
> >> But, since this is all with a web interface, it works well, only
> >> for web folks.
> >
dw>Which I can programmatically feed and get the contents of your lists
dw>in less time that it'd take via e-mail. Sorry, no cigar. A web i/f is
dw>no protection at all.

I interpreted the assertion to be "since this is a (manual) web
interface, it's not practical to extract addresses using it because it
would be very time consuming." My point is that CGI programs can be fed
from other programs, no browser and no "pointing and clicking" involved,
so they don't provide any inherent security.

I haven't studied the Majorcool source to see what sort of security
problems it contains (no time for such games, that's the author's job
:-) ), but from a quick peek at the posted URL, it appears that Mjcool
side-steps the issue by disallowing all sorts of otherwise valid address
forms. While that may limit its security exposure, it also limits its
application and usefulness, and it still doesn't prevent anyone from
finding out if any specific address is subscribed to a given list.

-- 
 Dave Wolfe


Follow-Ups:
Indexed By Date Previous: Re: Is 'wh*ch' useful?
From: Jason L Tibbitts III <tibbs@hpc.uh.edu>
Next: Re: Is 'wh*ch' useful?
From: Brock Rozen <brozen@torah.org>
Indexed By Thread Previous: Moderated Not Working
From: system administrator account <root@axe.humboldt.edu>
Next: Re: Is 'wh*ch' useful? --> moved from -work
From: Jason L Tibbitts III <tibbs@hpc.uh.edu>

Google
 
Search Internet Search www.greatcircle.com