N
Nomen Nescio
WHY ? No one needs this outdated crap anymore.
3 lines of PHP can do what shitty formmail does and better and more safely.
Formmail is the spammers choice, formmail is so controversial that many hosts
ban it outright.
Clunky, outdated shit and if you have an old version it is full of holes and
exploits for hackers and spammers.
**** of formmail you suck. Totally pointless useless shit. go away formmail
3. Matt Wright Formmail attack
The Formmail package has become a favorite tool of spammers.
Formmail allows a website to email form submissions to an email account. If
left unpatched a malicious user can send spam simply by including the list
of target email addresses in an HTTP request to Formmail. This behavior makes
tracking down the origin of the spam difficult because the only place the spammers
IP address is saved is in the Web logs of the affected site.
FormMail is a widely-used web-based e-mail gateway, which allows form-based
input to be emailed to a specified user.
When the form is submitted, the commands will be executed on the host, with
the privileges of the webserver process. This might be leveraged by the attacker
to gain local access to the host.
http://www.securityfocus.com/corporate/research/top10attacks_q1_2002.shtml
3 lines of PHP can do what shitty formmail does and better and more safely.
Formmail is the spammers choice, formmail is so controversial that many hosts
ban it outright.
Clunky, outdated shit and if you have an old version it is full of holes and
exploits for hackers and spammers.
**** of formmail you suck. Totally pointless useless shit. go away formmail
3. Matt Wright Formmail attack
The Formmail package has become a favorite tool of spammers.
Formmail allows a website to email form submissions to an email account. If
left unpatched a malicious user can send spam simply by including the list
of target email addresses in an HTTP request to Formmail. This behavior makes
tracking down the origin of the spam difficult because the only place the spammers
IP address is saved is in the Web logs of the affected site.
FormMail is a widely-used web-based e-mail gateway, which allows form-based
input to be emailed to a specified user.
When the form is submitted, the commands will be executed on the host, with
the privileges of the webserver process. This might be leveraged by the attacker
to gain local access to the host.
http://www.securityfocus.com/corporate/research/top10attacks_q1_2002.shtml