(keitai-l) Re: bwute! [i-mode ssh]

From: Thomas O'Dowd <tom_at_nooper.com>
Date: 12/13/01
Message-ID: <20011213120434.O17132@beast.uwillsee.com>
Nice try but not exactly secure me thinks... Firstly smtp is easy
to fake so just because it appears from your imode keitai doesn't mean
its from your imode keitai. So if I knew the address to send it to
and a bit about your procmail settings, even though you get the
stdout, I could probably run a couple of extra commands on your box
and email myself in the process. You can do this of course but I
wouldn't advertise it or give anyone your procmailrc :) Still nice hack.

Tom.

On Thu, Dec 13, 2001 at 03:42:24AM +0100, Wolfgang Slany wrote:
> 
> I know the following is a suboptimal hack but it does exactly what I want.
> 
> On my unix box I have a procmail script that, when a specially formatted
> mail from *my* imode keitai reaches it, executes whatever commands that
> are written in the mail body. The stdout is then sent back to my handy
> email address.  This avoids the need to type in a password, so security is
> not breached. Of course network sniffers could read these mails (but no
> passwords are transmitted), and editing is limited to the level of
> sh/ed/ex/sed/perl/wget etc, but it is amazing how much one can do with
> these tools and some regex'es.
> 
> If someone is interested, I can send the .procmailrc snippet.
> 
> Best regards, Wolfgang
> 
> Wolfgang SLANY mailto:slany@lixto.com
> http://www.lixto.com/
> 
> /
> 
> Wolfgang SLANY mailto:wsi@dbai.tuwien.ac.at
> http://www.dbai.tuwien.ac.at/staff/slany/
> 
> 
> This mail was sent to address tom@nooper.com
> Need archives? How to unsubscribe? http://www.appelsiini.net/keitai-l/ 
> 

-- 
Thomas O'Dowd. - Nooping - http://nooper.com
tom_at_nooper.com - Testing - http://nooper.co.jp/labs
Received on Thu Dec 13 05:12:27 2001