Mail Security Issue

Mail Security Issue

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Mail Security Issue The Doctor 07-29-2004
Posted by The Doctor on July 29, 2004, 10:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have the following scenario:

On a Secure Web Site, we have an e-mail sign up form.

The person wanting to develop this is concerned about spammer intercepting
the e-mail address of signee.

We are using Apache and SSL.

What issues should myself, the system admin, and the developer be looking
out for and how far can we secure this site.
--
Member - Liberal International        
This is doctor@nl2k.ab.ca        Ici doctor@nl2k.ab.ca
God Queen and country! Beware Anti-Christ rising!
Microsoft is not the solution; it is the question; what is the answer?? NO!!


Posted by Paul Rubin on July 29, 2004, 3:48 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
doctor@edmontonab.ca (The Doctor) writes:
> On a Secure Web Site, we have an e-mail sign up form.
>
> The person wanting to develop this is concerned about spammer intercepting
> the e-mail address of signee.
>
> We are using Apache and SSL.
>
> What issues should myself, the system admin, and the developer be looking
> out for and how far can we secure this site.

Spammers do some pretty awful things, but I haven't yet heard of them
snooping other people's IP connections. At least in the US, that
would constitute an illegal wiretap and be a felony. I think users
will generally be much more concerned about your site releasing
(e.g. selling) their addresses to spammers, than they are concerned
about spammers intercepting the addresses in transit.


Posted by Claire Tucker on July 29, 2004, 10:38 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On Thu, 29 Jul 2004 22:28:54 +0000 (UTC), doctor@edmontonab.ca (The
Doctor) wrote:

>I have the following scenario:
>
>On a Secure Web Site, we have an e-mail sign up form.
>
>The person wanting to develop this is concerned about spammer intercepting
>the e-mail address of signee.
>
>We are using Apache and SSL.
>
>What issues should myself, the system admin, and the developer be looking
>out for and how far can we secure this site.

You've cross-posted this to several groups which have very different
focuses, and so I can't tell what point of view you're thinking of
here.

You say you are using SSL, so presumably you aren't concerned about
the address being submitted from the browser to the web server. I
guess, then, that you must be thinking of the outgoing mail.

You aren't exactly clear about what your site is doing. I *think* what
you're saying is that you're asking for an email address and then
presumably sending mail to the new user, perhaps to "validate" the
given email address.

In this case, there's not really much you can do about the mail
transfer; SMTP in general operates over unencrypted links, and the
mail you're sending could pass through several mail servers before it
reaches its ultimate destination. If this concerns you, then I have to
say that perhaps your only option is to not send the mail at all.

Assuming I've got your focus and situation right here, I'm going to
trim the followups to comp.security.misc which seems to be the only
applicable newsgroup you crossposted to.

All the best,
-Claire


Similar ThreadsPosted
Do you have Windows security software issue?? Here is the solution April 14, 2008, 1:08 am
Call for Papers: Special Issue on Security Certification January 26, 2006, 11:20 pm
ISO 17799 / ISO 27001 Security News: Issue 12 Released September 26, 2006, 11:28 am
What's the basic security issue with an unsecured home router? May 26, 2008, 1:13 am
Call for papers: Special Issue on: "Data and Application Security" October 21, 2006, 1:20 pm
Symantec Gateway Security 5400 device and rDNS issue May 10, 2007, 1:11 pm
Mail Security May 23, 2004, 8:44 am
HTML Form Mail and Security November 17, 2005, 2:21 pm
how to fix the sound issue October 18, 2005, 11:45 am
snort - library issue??? May 12, 2004, 2:43 pm

The site map in XML format XML site map

Contact Us | Privacy Policy