Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Unsanitized web form mailers are a common source of spam mails, in particular if that form allows specifying an arbitrary email address to send the mail to. Essentially what the website owner meant to do was sending an innocent email (maybe for leaving feedback, or for a signup link), and the email text then gets mangled by the spammer in a way that you are seeing a link to product they want you to buy. It is not a vulnerability in the sense that it leads to malicious code being executed, but it allows spammers to send their spam links through "reputable" email sources, increasing the likelihood that it will make it through spam filters.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: