Re: WWW Security Hole

Martin Hamilton <>
Date: Thu, 12 Aug 1993 18:10:52 +0100 (BST)
From: Martin Hamilton <>
Sender: Martin Hamilton <>
Reply-To: Martin Hamilton <>
Subject: Re: WWW Security Hole
To: Marc VanHeyningen <>
In-reply-to: <>
Message-id: <Pine.3.07.9308121851.I16016-9100000@lust>
Mime-Version: 1.0
Status: RO
Marc VanHeyningen said:

> - Is plain gopher sans WWW vulnerable to this same problem?  Do they
>   know about it?  If not, telling them (and also CERT) would be a good idea.

I've just verified this myself.  Oops!!


How about patching clients so they have a list of "dodgy ports",
like SMTP, and ask the user whether to carry on if they get given
a URL that points to one?