TIP: Click on subject to list as thread! ANSI
echo: fidosoft.husky
to: Joe Delahaye
from: mark lewis
date: 2015-03-15 13:16:04
subject: Unpacking insecure arcmail

On Sat, 14 Mar 2015, Joe Delahaye wrote to mark lewis:

 JD>> If indeed it would be a mail bomb, then unpacking it first before 
 JD>> tossing would still create problems I would think.

 ML> that's why the tosser simply inspects the bundle to see what the 
 ML> compression ratio is before unpacking... it seems that many 
 ML> developers have forgotten how to do these common things as has 
 ML> been done since at least the 90s...

 JD> I think more likely the thought of mailbonbs as a threat no longer 
 JD> exists.

never let your guard down... we might be smaller than the net was in years
past when two well known folks got into a controversy and one set up their
mailer to send $CLOCK to the other... $CLOCK is a never ending
psuedo-file... it was documented in the snooze IIRC... i know i've read it
several times... this was one of the things that lead to mailer developers
to not allow such psuedo-files to be attached like this...

)\/(ark

* Origin: (1:3634/12)
SEEN-BY: 11/201 34/999 90/1 116/18 120/331 123/500 1406 128/187 135/364 140/1
SEEN-BY: 218/700 222/2 226/0 160 230/150 240/1120 249/303 250/1 261/38 100
SEEN-BY: 266/404 1413 267/155 280/464 1027 282/1031 1056 292/907 908 311/2
SEEN-BY: 320/119 340/400 393/68 396/45 633/267 280 640/384 712/101 550 848
SEEN-BY: 770/1 801/161
@PATH: 3634/12 123/500 261/38 712/848 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.