Re: Unsubscribe DoS

From: John Dow (jmdat_private)
Date: Sat Dec 21 2002 - 01:48:51 PST

  • Next message: Vinay A. Mahadik: "Query: BID 6273: PortailPhp SQL Injection Vulnerability."

    ----- Original Message -----
    From: "Arnold, Jamie" <harnoldat_private>
    To: "'Frank Knobbe'" <frankat_private>; <vuln-devat_private>
    Sent: Saturday, December 21, 2002 12:19 AM
    Subject: RE: Unsubscribe DoS
    
    
    > Many of these "unsubscribe" urls are just a way of verifying that the
    email
    > address is a valid one.  Probes, of a sort.
    
    Indeed - ever noticed how spammers offering "verified" email addresses
    charge more for their mailing lists?
    
    It's a quandry we're in at the moment - the company I work for (we build and
    host websites) have some custom written software for mailing visitors to
    sites who have double opted in to mailing lists run by the sites, but even
    with this double opt in there are always people who have forgotten they've
    done it and want off the list. We provide an unsubscribe link (which does
    what it's supposed to) but also add an X-Header that is a message from the
    systems team saying "We're trying to do this as responsibly as possible, etc
    etc".
    
    I don't like being involved in this, but there given there isn't much I can
    do about it, I'm at least trying to do it as responsibly as possible.
    
    J
    
    --
    John Dow
    http://www.nelefa.org
    http://www.miserable-bastard.com
    



    This archive was generated by hypermail 2b30 : Sun Dec 22 2002 - 11:42:23 PST