|
|
Log in / Subscribe / Register

Security

Brief items

Fixing spam with the legal code

As the spam situation continues to worsen, more people are looking farther afield for potential solutions. Recently there has been a new surge in interest in legal solutions. When all else fails, pass a law.

One of the current approaches is the Lofgren law (backed by Lawrence Lessig) which would require all spam to carry an "ADV:" tag in the subject line. Recipients of untagged spam could report it to the U.S. Federal Trade Commission, and, perhaps, receive a portion of any fines collected from the spammer. The bill has numerous problems, including an overbroad definition of "spam" and the fact that the FTC already is unable to do anything about the vast number of complaints it receives.

The state of Virginia has taken things further with a law that makes spamming with forged headers into a felony. Spammers could find themselves spending the next five years contemplating the benefits of anatomical enlargement in a prison cell. To qualify for this penalty, a spammer would have to send out at least 10,000 messages with forged headers in a single day.

Creating legal tools to shut down spammers may be helpful in a few cases, but it is hard to see much long-term benefit coming from the legislative approach. What reason is there to believe that the legal system will be any more effective at shutting down spam than it is, say, at stopping the distribution of DeCSS? Even after an international campaign making even linking to DeCSS a crime, the DVD decryption software remains readily accessible. When all a spammer needs is a dialup connection and an open relay anywhere in the world, the effectiveness of any country's laws will be limited.

Comments (8 posted)

New vulnerabilities

balsa: imap code buffer overflow

Package(s):balsa CVE #(s):CAN-2003-0140 CAN-2003-0167
Created:April 30, 2003 Updated:May 7, 2003
Description: Balsa, it turns out, suffers from the same buffer overflow found in mutt; see the mutt vulnerability information for details.
Alerts:
Debian DSA-300-1 balsa 2003-05-06
Conectiva CLA-2003:635 balsa 2003-04-30
Gentoo 200304-10 balsa 2003-04-30

Comments (none posted)

Bugzilla: several vulnerabilities.

Package(s):bugzilla CVE #(s):
Created:April 30, 2003 Updated:May 21, 2003
Description: The Bugzilla bug tracking system has a new set of vulnerabilities which can lead to cross-site scripting and symlink attacks. Versions 2.16.3 and 2.17.4 contain the necessary fixes; see this advisory for the details.
Alerts:
Conectiva CLA-2003:653 bugzilla 2003-05-21

Comments (none posted)

Monkey HTTPd Remote Buffer Overflow

Package(s):monkeyd CVE #(s):
Created:April 28, 2003 Updated:April 30, 2003
Description: A buffer overflow vulnerability exists in Monkey's handling of forms submitted with the POST request method. The unchecked buffer lies in the PostMethod() procedure. The advisory contains more information.
Alerts:
Gentoo 200304-07 monkeyd 2003-04-28

Comments (none posted)

PoPTop: remotely exploitable buffer overflow

Package(s):pptpd CVE #(s):CAN-2003-0213
Created:April 28, 2003 Updated:June 6, 2003
Description: The PoPToP PPTP server contains a remotely exploitable buffer overflow; read the full advisory for more information.
Alerts:
SuSE SuSE-SA:2003:029 pptpd 2003-06-06
Debian DSA-295-1 pptpd 2003-04-30
Gentoo 200304-08 pptpd 2003-04-28

Comments (none posted)

squirrelmail: more cross-site scripting vulnerabilities

Package(s):squirrelmail CVE #(s):CAN-2003-0160
Created:April 24, 2003 Updated:June 4, 2003
Description: SquirrelMail is a webmail package written in PHP. Multiple vulnerabilities have been found which affect versions of SquirrelMail shipped with Red Hat Linux 8.0 and Red Hat Linux 9.

Cross-site scripting vulnerabilities in SquirrelMail version 1.2.10 and earlier allow remote attackers to execute script as other Web users via mailbox displays, message displays, or search results displays. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0160 to these issues.

All users are advised to upgrade to these errata packages containing SquirrelMail version 1.2.11, which is not vulnerable to these issues.

Alerts:
Yellow Dog YDU-20030602-2 squirrelmail 2003-06-02
Red Hat RHSA-2003:112-01 squirrelmail 2003-04-24

Comments (none posted)

Events

Call for Papers: Chaos Communication Club Camp 2003

The Chaos Communication Club Camp is happening near Berlin on August 7 through 10. The call for papers has gone out, with papers due by July 1. "Lectures are expected to be highly relevant in practice or better be darn funny. Sales droids have been known to disappear without traces on past events."

Full Story (comments: none)

Page editor: Jonathan Corbet
Next page: Kernel development>>


Copyright © 2003, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds