  Steve Security is inefficient Consultant join:2001-03-10 Tustin, CA
| reply to Sleeve1 Re: The Fight - It's Payback Time!
said by sleeve :Have you run it yet Steve? No: I don't ever run code from random people on the internet. Ever. I don't know enough about Flash to trust it when I don't know what it does.
This is not any reflection on you, but a security paranoia that has served me well for a long time.
The potential for abuse is a fair concern, and I'm not sure how one could release DoS tool but see that it be used only for good. So I guess I'll be left with waiting for some of the spam in question and rolling my own in perl. I did this some time ago for an unrelated web-form-submittal purpose, so modifying the code should be straightforward.
This whole approach is less useful when the webform saves the entry in a database along with IP - easy to DELETE FROM spamee WHERE IP = '10.1.1.3'.
But if it's a mailform that generates one email per submission, it sounds like a positively lovely idea.
Steve -- Stephen J. Friedl Unix Wizard Microsoft Security MVP Tustin, California USA my web site |