Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

The gentlemen looked one another over with microscopic carelessness.


dovenet / Internet / eTransfer msg section, pretty lame

SubjectAuthor
o eTransfer msg section, pretty lameOgg

1
eTransfer msg section, pretty lame

<61944442.4988.dove-int@capitolcityonline.net>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=549&group=DOVE-Net.Internet#549

  copy link   Newsgroups: DOVE-Net.Internet
From: ogg@VERT/CAPCITY2 (Ogg)
To: All
Subject: eTransfer msg section, pretty lame
Message-ID: <61944442.4988.dove-int@capitolcityonline.net>
Date: Tue, 16 Nov 2021 11:52:00 -0500
X-Comment-To: All
Path: rocksolidbbs.com!not-for-mail
Newsgroups: DOVE-Net.Internet
X-FTN-AREA: DOVE-INTERNET
X-FTN-PID: OpenXP/5.0.50 (Win32)
X-FTN-MSGID: 723:320/1.9@dovenet f679aaed
X-FTN-CHRS: ASCII 1
X-FTN-SEEN-BY: 320/1
WhenImported: 20211116203948-0800 41e0
WhenExported: 20211116225744-0800 41e0
ExportedFrom: VERT dove-int 8322
WhenImported: 20211116185234-0500 412c
WhenExported: 20211116233952-0500 412c
ExportedFrom: CAPCITY2 dove-int 4988
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 8bit
 by: Ogg - Tue, 16 Nov 2021 16:52 UTC

An eTransfer typically allows for entering a short message of
up to 400 chars. For a recent eTransfer, I found it important
to enter something to reference the billing statement that I am
paying for. My typical message was something like this:

This payment is for the "60-90 days" portion of the
statement dated 11/15/21.

But that triggered an error message:

"There appears to be an error! All errors must be corrected
before continuing."

Please enter a valid message. It must not exceed 400
characters and contain only letters, numbers, and the
characters . ! @ / ; : , ' = $ ^ ? * ( ). It must not
contain the words http:, https:, www., javascript,
function, return.

In this case it seemed that the quote char and the dash was not
on the allowed list. Now, I'm just wondering WHY would a quote
or dash char need to be treated differently and excluded from a
valid set?

Likewise, why would even a simple word like function or return
be a problem for a message block? When the system dedicates a
400 char block for a message, why can't the system simply treat
that content as a benign group of chars and ignore any
"functionality" implied with http: https: or www, etc?

Could there be hacking vectors that haven't been solved in the
eTransfer system?

--- OpenXP 5.0.50
* Origin: Ogg's Dovenet Point (723:320/1.9)
� Synchronet � CAPCITY2 * capcity2.synchro.net * Telnet/SSH:2022/Rlogin/HTTP

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor