RE: Unsubscribe DoS

From: Arnold, Jamie (harnoldat_private)
Date: Fri Dec 20 2002 - 16:19:22 PST

  • Next message: Frank Knobbe: "Unsubscribe DoS"

    Many of these "unsubscribe" urls are just a way of verifying that the email
    address is a valid one.  Probes, of a sort.
    
    Jamie
     
    ~~Ipsa scientia potestas est~~
     
    ~~Knowledge itself is power~~
     
    <>~<
    
    
    -----Original Message-----
    From: Frank Knobbe [mailto:frankat_private] 
    Sent: Thursday, December 19, 2002 12:35 AM
    To: vuln-devat_private
    Subject: Unsubscribe DoS
    
    
    
    Greetings,
    
    while reviewing postmasters email for a mail system we manage, I came across
    an email from some list/spam server that offers an unsubscribe URL. This was
    a bounced email for a user that no longer has a mail box on the systems. So
    I just opened the browser and unsubscribed the user to avoid any further
    bounces.
    
    Nice feature I thought..... and then I started to take a look at the URL
    [1]. Obviously we have the subscriber ID (email recipient), the customer ID
    (the client of the list/spam server), and the campaign ID (to identify the
    mailing itself). 
    
    The risk is that someone could just enter any subscriber ID and unsubscribe
    someone else.
    
    That made me wonder how widespread the problem is. Are there any pointers or
    references to list/spam server opt-in/opt-out systems that are prone to
    automated attacks, such as a for-loop posting http pages?
    
    Regards,
    Frank
    
    
    [1]http://mailiwant.com/unsubscribe.jsp?subid=123456&custid=12&campid=1234
    



    This archive was generated by hypermail 2b30 : Fri Dec 20 2002 - 19:52:20 PST