Great Circle Associates List-Managers
(March 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Security Problems
From: Tim Pesce <tpesce @ well . sf . ca . us>
Organization: Whole Earth 'Lectronic Link
Date: Tue, 14 Mar 1995 11:00:07 -0800 (PST)
To: oceania @ enet . net (Eric Klien)
Cc: list-managers @ GreatCircle . COM
In-reply-to: <199503141802.LAA05738@pinyon.enet.net> from "Eric Klien" at Mar 14, 95 11:02:14 am

> I am working on changing the code of majordomo by hand to solve some 
> major security problems with it.  The problems that I have are that 
> 1) anyone can post to the list by sending e-mail to list-l-outgoing 
> and 2) anyone can get a copy of the list by sending majordomo telnet 
> client 25, expn listname-outgoing even if I disable the who command 
> in majordomo.  
> 
> Can anyone give suggestions on solving the above problems?

Suggestion for problem #2:

If you are using V8 sendmail as your MTA, it can be configured to disallow
the SMTP expn operation.  This is also useful in many contexts other than
mailing lists and Majordomo.  Take a look at the p (privacy) option, and
especially the "noexpn" argument.

Granted, this will need to be done systemwide, and if you aren't the sys.
admin. for your site, you'll need to convince someone else of the validity
of this solution.  I think, however, the arguments in favor of enabling
this behavior outweigh the arguments against it.

Hope this helps!

Tim

-- 
Tim Pesce		Whole Earth 'Lectronic Link	(415) 332-4335 VOICE
System Administrator	1750 Bridgeway Suite A200	(415) 332-4927 FAX
tpesce@well.sf.ca.us	Sausalito, CA 94965-1900


Follow-Ups:
References:
Indexed By Date Previous: Re: Security Problems continued
From: Dave Barr <barr@math.psu.edu>
Next: Security
From: Eric Klien <oceania@enet.net>
Indexed By Thread Previous: Re: Security Problems
From: Dave Barr <barr@math.psu.edu>
Next: Re: Security Problems
From: mcb@postmodern.com (Michael C. Berch)

Google
 
Search Internet Search www.greatcircle.com