home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.mail.elm
- Path: sparky!uunet!cis.ohio-state.edu!pacific.mps.ohio-state.edu!linac!uchinews!machine!chinet!les
- From: les@chinet.chi.il.us (Leslie Mikesell)
- Subject: Re: elm wish list
- Message-ID: <BxGsGJ.I58@chinet.chi.il.us>
- Organization: Chinet - Public Access UNIX
- References: <1992Nov5.023642.5435@DSI.COM> <Bx9GEr.C5M@ars2.uucp> <syscrc.721158601@gsusgi1.gsu.edu>
- Date: Mon, 9 Nov 1992 19:50:42 GMT
- Lines: 37
-
- In article <syscrc.721158601@gsusgi1.gsu.edu> syscrc@pickle.gsu.edu (Randy Carpenter) writes:
-
- [Re: having ELM generate From: to match the TO: alias]
-
- >Wouldn't this suggested feature allow allow an e-mail security hole? For
- >example, a bad guy could type in a fake letter complete with headers from
- >another person (i.e. a fake "To:" line). Let's say he uses "To: root".
- >Then, store it in a folder, reply to it and Elm would put "From: root" in
- >the headers?
-
-
- Remember that ELM is just the "user agent" for mail and thus can't be
- responsible for managing the security of your header lines. You can
- just as easily type the headers and body into the editor of your choice
- and feed them directly to the transport program: mail, sendmail or
- whatever your site uses. Some versions of the transport programs check
- that the From: line matches the sender, some don't. Most of the
- ones that do check just add a Sender: line noting the real user name
- and they can generally be fooled if you work at it.
-
- Still, I don't see this as a good idea unless it is controlled by a
- file containing a list of aliases that you receive under and the
- headers you would like forced when you reply to them. For example
- if I received mail as part of a "support" group I'd still want the
- From: to indicate my name, but I'd want a "Reply-To: support" line
- inserted. On the other hand, messages aliased to a mailing list
- probably shouldn't be changed at all - you certainly don't want those
- to be modified so that your reply appears to have come from the
- list address!
-
- Personally, I'd like to have the choice of including the header lines
- in the edit buffer (like rn's 'R' command gives you) even if this
- turns off the ability to use ELM's header editor. People using rn
- or trn for news would already be used to the concept.
-
- Les Mikesell
- les@chinet.chi.il.us
-