[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Contact form linking from "From:" header



Earl Hood wrote:
On January 9, 2004 at 16:09, Gunnar Hjalmarsson wrote:
2) The contact form script uses the message ID to grab the
"From:" header from .mhonarc.db.

Note, you can probably avoid reading the .mhonarc.db, since it is not efficient for large archives.

You can setup your script to just parse out the information from the <!--X- ...--> comment headers at the top of a mhonarc message page.

Hmm.. Yes, I see that now. Thanks for the tip.


So far, my thinking about possibly large database files has been that
the buttons won't probably be used that much, so the resulting server
load shouldn't be a problem. But you are right, the info is available
in those comment headers.

What bothers me about it is that since I can easily parse - and
deobfuscate - the from addresses, so can the spammers...  So I can't
help wondering what the "X-From-R13:" header is normally used for, and
if it's really needed. ;-)

--
Gunnar Hjalmarsson
Email: http://www.gunnar.cc/cgi-bin/contact.pl



[Index of Archives]     [Bugtraq]     [Yosemite News]     [Mhonarc Home]