gopher and similar holes caused by writing to URL-specified portsKeith Moore <email@example.com>
Subject: gopher and similar holes caused by writing to URL-specified ports
From: Keith Moore <firstname.lastname@example.org>
Date: Fri, 13 Aug 1993 13:55:51 -0400
Given that gopher servers already exist on many random ports, it seems like
simply restricting ports isn't quite the right solution.
I realize this is somewhat up to the gopher guys, but how about declaring
that: any gopher URL that (a) specifies a port other than the "standard"
gopher port, and (b) includes a newline, is not valid?
Do gopher servers really (in practice) accept newlines in query strings?