On Fri, 7 Feb 2003, Istvan Berkeley wrote:
> Hi there,
> There is a report of a major security hole in most versions of Majordomo
> available at http://www.net-security.org/vuln.php?id=2416 I suggest
> folks get on top of this, otherwise the evil spammers may make our lives
> even more hellish.
I know that this was discussed on the MD list many years ago. I know that
I modified a local copy of MD to set which access to list and also to
return no more than 5 matches (if I recall correctly) many years ago.
But I agree with the report that it is bad design to have the default so
open.
-j
--
Jeffrey Goldberg http://www.goldmark.org/jeff/
Relativism is the triumph of authority over truth, convention over justice
Hate spam? Boycott MCI! http://www.goldmark.org/jeff/anti-spam/mci/
References:
|
|