Procmail feature security hole?
Brought to you by:
ftobin
|
From: Billy D. <bi...@da...> - 2000-10-03 04:55:16
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 > -----pgpenvelope processed message----- > > I agree to pay you $1,000,000 dollars. > > -- > "The Funk, the whole Funk, and nothing but the Funk." > Linux barcode software mirror: http://dadadada.net/cuecat > Billy Donahue <mailto:bi...@da...> > > -----pgpenvelope information----- > Hash: SHA1 > Version: GnuPG v1.0.3 (GNU/Linux) > Comment: pgpenvelope 2.9.0 - http://pgpenvelope.sourceforge.net/ > > gpg: Signature made Tue Oct 3 00:45:07 2000 EDT using DSA key ID 0219745D > gpg: Good signature from "Billy Donahue <bi...@bi...>" > gpg: aka "Billy Donahue <bi...@da...>" > gpg: aka "Billy Donahue <bi...@es...>" > gpg: aka "Billy Donahue <bi...@bi...>" > > pgpenvelope_decrypt: message processed at Tue Oct 3 00:45:10 2000 > > -----end pgpenvelope information----- > If I send this forged message to someone using the procmail script, They will have no indication that it wasn't really decrypted by pgpenvelope (other than the fact that it doesn't show up in the pgpenvelope-backup folder). The forged message will look like pgpenvelope verified it. By the way, I believe that as of Oct 1, 2000, 'digital signatures' (whatever that means) are legally binding. - -- "The Funk, the whole Funk, and nothing but the Funk." Linux barcode software mirror: http://dadadada.net/cuecat Billy Donahue <mailto:bi...@da...> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.3 (GNU/Linux) Comment: pgpenvelope 2.9.0 - http://pgpenvelope.sourceforge.net/ iD8DBQE52Wav+2VvpwIZdF0RAr6TAKCgSueiGlD7SpV9AFteuO0EyQZbEACaAhjc 1tU9NRrcw85Q5Tc5yQiW2Vc= =YtIA -----END PGP SIGNATURE----- |