Re: Image extension issue in mime.php
"Paul Lesniewski" <[email protected]>
| Newsgroups | gmane.mail.squirrelmail.devel |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Aug 21, 2008 at 2:58 AM, Thijs Kinkhorst <[email protected]> wrote: > On Thu, August 21, 2008 03:30, Paul Lesniewski wrote: >> My feeling is that this should be addressed by either removing the >> restriction list completely, > > I would say "yes" to this, but would be curious where the original idea > comes from. Isn't that tracable in the commit log? It's your commit, so maybe you can help. http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/functions/mime.php?view=log#rev12370 If this code is meant to stop "request forgeries through included images", I'd like to know more about what this means, since, as I noted, it wouldn't be hard for an attacker to substitute a dynamically executed script for an "image" file on the target server. Or perhaps the file extension code is not specifically what fixed that actual issue and is only a side effect? So if the extension limitation on image files is removed, does this expose SM to some XSS or something that it's not already exposed to now? ------------------------------------------------------------------------- This SF.Net email is sponsored by the Moblin Your Move Developer's challenge Build the coolest Linux based applications with Moblin SDK & win great prizes Grand prize is a trip for two to an Open Source event anywhere in the world http://moblin-contest.org/redirect.php?banner_id=100&url=/ ----- squirrelmail-devel mailing list Posting guidelines: http://squirrelmail.org/postingguidelines List address: [email protected] List archives: http://news.gmane.org/gmane.mail.squirrelmail.devel List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-devel