[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: learn procmail and quit whining already (was Re: Debian lists and Cc'ing people in replies in addition to the list)



Louis-David Mitterrand <vindex@apartia.org> writes:

> 3) you have the option of having a separate dupe cache for each mailing
> list:
>
> 	:0 Whc: msgid.lock
> 	| formail -D 8192 msgid.$LIST

You do realize this creates a fairly easy way for people to abuse your
filter?  If an attacker can predict the Message-ID of an email someone
is going to send to you, then they can easily send you a message with
that Message-ID, and your filter will happily delete their mail when
it arrives, and you will be none the wiser.  Many people's Message-IDs
are fairly easy to predict.

I don't see the point of complicated and fragile mail-filtering when
the problem could be solved in the first place by just not sending
duplicate messages.






Reply to: