> On Thu, 28 Apr 1994, Arnold de Leon wrote:
> > Anyone who knows the name of the list can send mail to
> > the members directly. Sendmail version 8 makes it easier
> > for recipients to discover this name since it is very
> > good at recording envelope information in the
> > "Received" headers.
> >
> Thank for pointing out this additional "leak" in security for majordomo
> lists. Are there any other good list management programs which don't have
> these leaks and are practical to switch to?
>
Excuse me.... majordomo is not the culprit here. Sendmail is.
If you want perfect security on the Internet, pull the plug. Or do
as I do: my site is(was/will be) UUCP connected and unless you can
somehow gain physical access to teh console, there is no way you will
obtain the secret list name used for outgoing mail.
Andy
--
andy@genie.geis.com | Andy Finkenstadt, GEnie Sysop, GEnie Postmaster
andy@tml.com | Systems Engineer, TML Information Services, Inc.
genie@panix.com | +1 718-793-9099
Follow-Ups:
References:
|
|