[imp] Custom Reply-To header with multiple addresses?

Patrick Timmons ptimmons@courriel.polymtl.ca
Wed, 25 Oct 2000 11:24:49 -0400


Didn't think this one enough apparently. My first instinct is always to suspect
a security threat but your are right. We should never rely on any header but
those of SMTP agents under our control. Which means reading them from top to
bottom since the agents add them in front of what they receive.

Rich Lafferty wrote:
> 
> [Please remember to trim quoted text, folks, and reply *below* what
> you quote.]
> 
> [Lloyd Zusman asked about allowing users to add arbitrary headers..]
> 
> On Wed, Oct 25, 2000 at 10:26:34AM -0400, Patrick Timmons (ptimmons@courriel.polymtl.ca) wrote:
> > Any header they like ? Isn't there a security problem ?
> 
> Not unless you consider allowing users to use their own mail program a
> security problem -- that's a pretty common feature. I can't imagine
> which headers would cause security problems, though.
> 
>   -Rich
> 
> --
> ------------------------------ Rich Lafferty ---------------------------
>  Sysadmin/Programmer, Instructional and Information Technology Services
>    Concordia University, Montreal, QC                 (514) 848-7625
> ------------------------- rich@alcor.concordia.ca ----------------------
> 
> --
> IMP mailing list: http://horde.org/imp/
> Frequently Asked Questions: http://horde.org/faq/
> To unsubscribe, mail: imp-unsubscribe@lists.horde.org

-- 
Patrick Timmons, service informatique