verifycancel recycling for detecting forged cancels

Russ Allbery rra at stanford.edu
Fri Oct 1 06:10:35 UTC 2004


Christoph Biedl <cbiedl at gmx.de> writes:

> Finally I recalled verifycancel, an old option to protect against forged
> cancels, not very useful since it can be cheated easily and is therefore
> disabled in the default installation. The attached patch alters
> ARTcancelverify to check wheter at least one group in the cancel message
> can be found in article to be cancelled.
> This would still allow to cancel a Crosspost
> "alt.pets.cats.cute,alt.dogs.angry" using "alt.dogs.angry" but this does
> not happen that often.

I wanted to let you know that I have this patch but haven't thought enough
about it at the moment.  I'm deferring it for right now to my pending
patch queue since it's not eligible for INN 2.4.2.  Thank you very much
for it, though; it's something I do need to think about.

-- 
Russ Allbery (rra at stanford.edu)             <http://www.eyrie.org/~eagle/>

    Please send questions to the list rather than mailing me directly.
     <http://www.eyrie.org/~eagle/faqs/questions.html> explains why.


More information about the inn-workers mailing list