From owner-freebsd-current@FreeBSD.ORG Fri Dec 30 09:08:18 2005 Return-Path: X-Original-To: freebsd-current@freebsd.org Delivered-To: freebsd-current@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id AAA7216A41F for ; Fri, 30 Dec 2005 09:08:18 +0000 (GMT) (envelope-from des@des.no) Received: from tim.des.no (tim.des.no [194.63.250.121]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0502F43D53 for ; Fri, 30 Dec 2005 09:08:17 +0000 (GMT) (envelope-from des@des.no) Received: from tim.des.no (localhost [127.0.0.1]) by spam.des.no (Postfix) with ESMTP id 2BC4220A9; Fri, 30 Dec 2005 10:08:13 +0100 (CET) X-Spam-Tests: AWL,BAYES_00,FORGED_RCVD_HELO X-Spam-Learn: ham X-Spam-Score: -3.2/3.0 X-Spam-Checker-Version: SpamAssassin 3.1.0 (2005-09-13) on tim.des.no Received: from xps.des.no (des.no [80.203.243.180]) by tim.des.no (Postfix) with ESMTP id 0CB8420A8; Fri, 30 Dec 2005 10:08:13 +0100 (CET) Received: by xps.des.no (Postfix, from userid 1001) id A18D933C3E; Fri, 30 Dec 2005 10:08:12 +0100 (CET) To: Martin Cracauer References: <20051229193328.A13367@cons.org> <20051230021602.GA9026@pit.databus.com> <43B498DF.4050204@cyberwang.net> <43B49B22.7040307@gmail.com> <20051229220403.A16743@cons.org> From: des@des.no (=?iso-8859-1?q?Dag-Erling_Sm=F8rgrav?=) Date: Fri, 30 Dec 2005 10:08:12 +0100 In-Reply-To: <20051229220403.A16743@cons.org> (Martin Cracauer's message of "Thu, 29 Dec 2005 22:04:03 -0500") Message-ID: <86mzijdkar.fsf@xps.des.no> User-Agent: Gnus/5.110002 (No Gnus v0.2) Emacs/21.3 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable Cc: Barney Wolff , freebsd-current@freebsd.org, Sean Bryant Subject: Re: fetch extension - use local filename from content-disposition header X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 30 Dec 2005 09:08:18 -0000 Martin Cracauer writes: > The security implications are about the same as for the base > functionality. Any filename in the current directory can be wiped > out if you fetch or wget and a URL redirects to another URL which > leads to a filename that matches. No. Fetch uses the original filename as specified on the command line. Redirects are handled behind the scenes by libfetch. > The default behavior already *is* that the sending server has control > over your local naming. No. DES --=20 Dag-Erling Sm=F8rgrav - des@des.no