1 Return-Path: <amdragon@mit.edu>
\r
2 X-Original-To: notmuch@notmuchmail.org
\r
3 Delivered-To: notmuch@notmuchmail.org
\r
4 Received: from localhost (localhost [127.0.0.1])
\r
5 by olra.theworths.org (Postfix) with ESMTP id E988B431FAF
\r
6 for <notmuch@notmuchmail.org>; Thu, 19 Jan 2012 14:46:51 -0800 (PST)
\r
7 X-Virus-Scanned: Debian amavisd-new at olra.theworths.org
\r
11 X-Spam-Status: No, score=-0.7 tagged_above=-999 required=5
\r
12 tests=[RCVD_IN_DNSWL_LOW=-0.7] autolearn=disabled
\r
13 Received: from olra.theworths.org ([127.0.0.1])
\r
14 by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)
\r
15 with ESMTP id bhTHR+sfb31L for <notmuch@notmuchmail.org>;
\r
16 Thu, 19 Jan 2012 14:46:51 -0800 (PST)
\r
17 Received: from dmz-mailsec-scanner-3.mit.edu (DMZ-MAILSEC-SCANNER-3.MIT.EDU
\r
19 by olra.theworths.org (Postfix) with ESMTP id 6A7D4431FAE
\r
20 for <notmuch@notmuchmail.org>; Thu, 19 Jan 2012 14:46:51 -0800 (PST)
\r
21 X-AuditID: 1209190e-b7f7c6d0000008c3-9d-4f189d5b5e2f
\r
22 Received: from mailhub-auth-2.mit.edu ( [18.7.62.36])
\r
23 by dmz-mailsec-scanner-3.mit.edu (Symantec Messaging Gateway) with SMTP
\r
24 id 77.7C.02243.B5D981F4; Thu, 19 Jan 2012 17:46:51 -0500 (EST)
\r
25 Received: from outgoing.mit.edu (OUTGOING-AUTH.MIT.EDU [18.7.22.103])
\r
26 by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id q0JMkoMT028908;
\r
27 Thu, 19 Jan 2012 17:46:50 -0500
\r
28 Received: from awakening.csail.mit.edu (awakening.csail.mit.edu [18.26.4.91])
\r
29 (authenticated bits=0)
\r
30 (User authenticated as amdragon@ATHENA.MIT.EDU)
\r
31 by outgoing.mit.edu (8.13.6/8.12.4) with ESMTP id q0JMknXU016350
\r
32 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NOT);
\r
33 Thu, 19 Jan 2012 17:46:50 -0500 (EST)
\r
34 Received: from amthrax by awakening.csail.mit.edu with local (Exim 4.77)
\r
35 (envelope-from <amdragon@mit.edu>)
\r
36 id 1Ro0kZ-0004Ix-RR; Thu, 19 Jan 2012 17:46:31 -0500
\r
37 Date: Thu, 19 Jan 2012 17:46:31 -0500
\r
38 From: Austin Clements <amdragon@MIT.EDU>
\r
39 To: Aaron Ecay <aaronecay@gmail.com>, Pieter Praet <pieter@praet.org>
\r
40 Subject: Re: [PATCH] emacs: Quote MML tags in replies
\r
41 Message-ID: <20120119224631.GR16740@mit.edu>
\r
42 References: <1326998589-37187-1-git-send-email-aaronecay@gmail.com>
\r
43 <87wr8nuyam.fsf@praet.org>
\r
45 Content-Type: text/plain; charset=utf-8
\r
46 Content-Disposition: inline
\r
47 Content-Transfer-Encoding: 8bit
\r
48 In-Reply-To: <87wr8nuyam.fsf@praet.org>
\r
49 User-Agent: Mutt/1.5.21 (2010-09-15)
\r
50 X-Brightmail-Tracker:
\r
51 H4sIAAAAAAAAA+NgFlrKKsWRmVeSWpSXmKPExsUixG6nohs9V8LfYNVLTotpy7+wW1y/OZPZ
\r
52 4vfrG8wOzB47Z91l93i26hazR8e+y6wBzFFcNimpOZllqUX6dglcGSe3tDIW7OOvOH1jEksD
\r
53 43SeLkZODgkBE4m2jbOZIGwxiQv31rN1MXJxCAnsY5To6dvHAuFsYJRYu7CNHcI5ySQx4Xg/
\r
54 E4SzhFGit3cCUA8HB4uAqsSZJdEgo9gENCS27V/OCGKLCLhKbPu4jh3EZhaQlvj2uxlsnbCA
\r
55 qcTrrafBangFdCTerT4OViMkkCBx+fw/Zoi4oMTJmU9YIHrVJf7Mu8QMsgpkzvJ/HBBheYnm
\r
56 rbPByjmBSn5c/w42UlRARWLKyW1sExiFZyGZNAvJpFkIk2YhmbSAkWUVo2xKbpVubmJmTnFq
\r
57 sm5xcmJeXmqRrrFebmaJXmpK6SZGUGxwSvLtYPx6UOkQowAHoxIPL6erhL8Qa2JZcWXuIUZJ
\r
58 DiYlUV7tOUAhvqT8lMqMxOKM+KLSnNTiQ4wSHMxKIrwNfUA53pTEyqrUonyYlDQHi5I4r5rW
\r
59 Oz8hgfTEktTs1NSC1CKYrAwHh5IE70qQoYJFqempFWmZOSUIaSYOTpDhPEDDF4LU8BYXJOYW
\r
60 Z6ZD5E8xKkqJ8x4DSQiAJDJK8+B6YanrFaM40CvCvLdAqniAaQ+u+xXQYCagwR5NYiCDSxIR
\r
61 UlINjLN9r7P/1Kvf5bdw5bP4E8cVFrIVfZ4gN1Go41N86dYrl+PEQpU6xIStSzq7YracO1zt
\r
62 bPU97apavuRnVuepudKL/5ZHp0hfelOm4dDfZvZv7mQjhk1dx4Jmukxmn/bqhwurlnHMgVzl
\r
63 qS+/SVWZ3TLw5jR8G6Ccuy48NFx564ITDK9rOyPllFiKMxINtZiLihMBFJlgajgDAAA=
\r
64 Cc: notmuch@notmuchmail.org
\r
65 X-BeenThere: notmuch@notmuchmail.org
\r
66 X-Mailman-Version: 2.1.13
\r
68 List-Id: "Use and development of the notmuch mail system."
\r
69 <notmuch.notmuchmail.org>
\r
70 List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,
\r
71 <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>
\r
72 List-Archive: <http://notmuchmail.org/pipermail/notmuch>
\r
73 List-Post: <mailto:notmuch@notmuchmail.org>
\r
74 List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>
\r
75 List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,
\r
76 <mailto:notmuch-request@notmuchmail.org?subject=subscribe>
\r
77 X-List-Received-Date: Thu, 19 Jan 2012 22:46:52 -0000
\r
79 Quoth Pieter Praet on Jan 19 at 11:23 pm:
\r
80 > On Thu, 19 Jan 2012 13:43:09 -0500, Aaron Ecay <aaronecay@gmail.com> wrote:
\r
81 > > Emacs message-mode uses certain text strings to indicate how to attach
\r
82 > > files to outgoing mail. If these are present in the text of an email,
\r
83 > > and a user is tricked into replying to the message, the user’s files
\r
84 > > could be exposed.
\r
87 > > To demonstrate this, open a reply to this message then remove the
\r
88 > > exclamation marks after the hash marks below. Create a file in your
\r
89 > > home directory called passwd. Then press C-u M-x mml-preview. A
\r
90 > > (possibly base64-encoded) version of your ~/passwd file will replace
\r
91 > > the following lines:
\r
93 > > <#!part type="application/octet-stream" filename="~/passwd"
\r
94 > > disposition=attachment description=foo>
\r
97 > > It works equally well (and more dangerously) with /etc/passwd, but I
\r
98 > > didn't use that filename here to avoid the danger of someone
\r
99 > > accidentally attaching their /etc/passwd to a reply in this thread!
\r
101 > > emacs/notmuch-mua.el | 3 ++-
\r
102 > > 1 files changed, 2 insertions(+), 1 deletions(-)
\r
104 > > diff --git a/emacs/notmuch-mua.el b/emacs/notmuch-mua.el
\r
105 > > index d8ab822..c25c6b9 100644
\r
106 > > --- a/emacs/notmuch-mua.el
\r
107 > > +++ b/emacs/notmuch-mua.el
\r
108 > > @@ -115,7 +115,8 @@ list."
\r
110 > > (set-buffer-modified-p nil)
\r
112 > > - (message-goto-body))
\r
113 > > + (message-goto-body)
\r
114 > > + (mml-quote-region (point) (mark)))
\r
116 > > (defun notmuch-mua-forward-message ()
\r
117 > > (message-forward)
\r
119 > Wow, nice catch! You've just earned yourself a raise!
\r
127 > For some reason, `mml-quote-region' explicitly re-quotes
\r
128 > already quoted MML tags:
\r
130 > "<#!*/?\\(multipart\\|part\\|external\\|mml\\)"
\r
134 Probably so the transformation is invertible, though as far as I can
\r
135 tell there's no mml-unquote-region.
\r