Great Circle Associates Majordomo-Users
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: disable "who" command
From: Jason L Tibbitts III <tibbs @ hpc . uh . edu>
Date: 12 Jul 1996 21:46:58 -0500
To: J . F . L . Hopkinson @ dl . ac . uk
Cc: "Homer W. Smith" <homer @ lightlink . com>, peter @ ttc . nbs . gov
In-reply-to: "J. Hopkinson"'s message of Fri, 12 Jul 1996 11:09:09 +0100
References: <199607121009.LAA26864@mserv1.dl.ac.uk>

>>>>> "JH" == "J Hopkinson" <J.F.L.Hopkinson@dl.ac.uk> writes:

JH> ie. almost the exact contents of the lines in the alias file, not the
JH> contents of any file refered to there.  Is my system unusual ?

You're unusual in that you're using bulk_mailer.  If you had an :include:
statement, you'd (probably) get the entire list.  So in your case someone
cannot get the entire address list but they can bypass all of the content
checks and moderation you may have in place by sending mail straight to
your outgoing list (assuming that they could find its name, which you have
made quite difficult by using a secret name and hiding the resend options
in a file using the special resend `@' option).

JH> As others have noted you can also disable the vrfy and expn commands in
JH> sendmail.

With the setup you use, you can leave SMTP VRFY and EXPN enabled and still
be secure in the sanctity of your address list and your content checks.

There is another way to prevent spammers from sending to your outgoing
alias even if they know it's name.  You can change the "mailer" variable in
majordomo.cf to instruct Sendmail to use an alternate alias file (-oA
file), and have that file contain the outgoing alias.
-- 
      Jason L. Tibbitts III - tibbs@uh.edu - 713/743-8684 - 221SR1
System Manager:  University of Houston High Performance Computing Center
                1994 PC800 "Kuroneko"      DoD# 1723


References:
Indexed By Date Previous: Re: bin.bin list permission
From: Jason L Tibbitts III <tibbs@hpc.uh.edu>
Next: Re: Out of Memory?
From: Majordomo list server <majordom@gange.intesys.it>
Indexed By Thread Previous: Re: disable "who" command
From: "J. Hopkinson" <J.F.L.Hopkinson@dl.ac.uk>
Next: RE: disable "who" command
From: "dotun olaf <viper corporation >" <dotun@surfnet.demon.co.uk>

Google
 
Search Internet Search www.greatcircle.com