[Modsecurity] Formmail

Mike Cardwell modsecurity at blubbernet.com
Wed Apr 5 16:02:12 EDT 2006


* on the Wed, Apr 05, 2006 at 08:42:42PM +0100, Rob Shakir wrote:

> Perhaps the question is actually, whether a rule of this nature should
> be removed from the general distribution, or removed by the server
> administrator? This really depends on the reach of the rules - to be "on
> the safe side" it should probably be left in, and removed by an
> administrator who feels that their setup is formmail-safe.

I was kind of selfishly hoping that the rules would meet my requirements
so I wouldn't have to maintain the list my self. Stepping back and
looking at the situation though, I suppose the rules are more geared
towards sites that contain content you're aware of, rather than in a
mass hosting environment where you've no idea what's being run.

Mike

-- 
Digital photo printing: http://www.fotoserve.com/


More information about the Modsecurity mailing list