[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[leafnode-list] Re: Disabling The "Is Valid FQDN" Check

Am 10.05.2011 22:15, schrieb Adam Funk:
> On 2011-05-10, Matthias Andree wrote:
>> Am 10.05.2011 14:43, schrieb Adam Funk:
>>> On 2011-05-09, Matthias Andree wrote:
>>>> Unfortunately, depending on software installation, yes, newsd is one
>>>> example.  Leafnode 2 blacklists several software installations for
>>>> posting by pretending that the server's response had been "201 Posting
>>>> not allowed" when it got 200 in fact.
>>> Is that hard-coded in the source code somewhere?
>> Yes, it is. 
> Oh, I found it.  I've never encountered this problem, but the log
> messages in the source code look informative.  (Nice work again!)
>> I don't want script kiddies to wreak havoc in Usenet, so I 
>> don't make that configurable (you can already set "nopost = 1" in 
>> leafnode 1 and feedtype = none in leafnode 2).
> Good point.  (I guess anyone who can modify the source code or write a
> program to take advantage of that vulnerability doesn't count as a
> S.K.)

There are some who will be able to modify the source without
understanding the wider context, but there's always /something/
imperfect. :)
leafnode-list mailing list