<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://blog.teledyn.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>TeledyN - Blogspam II: MT as a relay - Comments</title>
 <link>http://blog.teledyn.com/node/1503</link>
 <description>Comments for &quot;Blogspam II: MT as a relay&quot;</description>
 <language>en</language>
<item>
 <title>Blogspam II: MT as a relay</title>
 <link>http://blog.teledyn.com/node/1503</link>
 <description>&lt;p&gt;Just when you thought it was safe to go back into the blogosphere, Jacques Distler tells us there&#039;s &lt;a title=&quot;Musings: More MT Spam Vulnerabilities&quot; href=&quot;http://golem.ph.utexas.edu/~distler/blog/archives/000252.html&quot;&gt;yet another spam vulnerability in MT&lt;/a&gt;: The web&#039;s most popular bloghosting platform can be used to send email, anonymously to anyone.&lt;/p&gt;

&lt;p&gt;And what&#039;s worse, there&#039;s no fix:&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;&lt;i&gt;Spammers can still send as much email as they want, with arbitrary message body content, to whomever they want, and do so completely anonymously. The only thing they can’t get rid of is the subject line ... which serves only to sully your reputation ...&lt;/i&gt;&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;Ben has posted a slightly &lt;a href=&quot;http://www.movabletype.org/downloads/mt-send-entry.zip&quot; title=&quot;click to download&quot;&gt;improved version&lt;/a&gt; but it&#039;s only a partial fix.  Unless you have good reason to use the email-this-page feature of &lt;span class=&quot;caps&quot;&gt;MT, &lt;/span&gt;the consensus is that you should remove or disable the &lt;span class=&quot;caps&quot;&gt;CGI &lt;/span&gt;until further notice.&lt;/p&gt;</description>
 <comments>http://blog.teledyn.com/node/1503#comments</comments>
 <category domain="http://blog.teledyn.com/taxonomy/term/6">the skin of culture</category>
 <pubDate>Wed, 26 Nov 2003 13:34:41 -0500</pubDate>
 <dc:creator>mrG</dc:creator>
 <guid isPermaLink="false">1503 at http://blog.teledyn.com</guid>
</item>
</channel>
</rss>
