Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I just spammed some guys by using this site. You may want to at least do a CAPTCHA. You or your ISP may receive complaints or get blacklisted if you're not careful.

Update: I also forged/made-up the from email address. Could have fun on an open wifi network with this. I suggest you stop, and think about all the ways this could be abused (and how you can prevent that) before proceeding.

Update2: The eamil "from header" actually has the forged address in it so if the recipient victim replies, the reply goes to the sender victim. Nice. The real culprit is clearly identified though:

X-Originating-IP: 173.193.132.135

Received: from heroku.com (unknown [10.9.180.5])

Update3: Sergey Brin is about to send an email to Zuck ;) just kidding.



Yes, email headers are not authenticated. Yes, mail filtering software accounts for this. Open wi-fi has nothing to do with it.


> Open wi-fi has nothing to do with it.

You should really serve the site in HTTPS.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: