Great Circle Associates Majordomo-Users
(June 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: How secure is "+confirm"?
From: Lazlo Nibble <lazlo @ swcp . com>
Date: Mon, 1 Jun 1998 11:31:14 -0600
To: mu <majordomo-users @ greatcircle . com>
Mail-followup-to: mu <majordomo-users@greatcircle.com>

How secure is the algorithm used with "+confirm" to generate auth keys?  One
of the list admins at the site that also hosts my lists is reporting that one
of his lists is getting a large number of *successful* bogus svbscriptions
despite being set to open+confirm.  The site in question is a frequent target
of svbscription-bombing software -- is it possible that someone's written
something that can figure out what the auth key "should" be, and can
successfully svbscribe someone against their will by sending a normal request
followed by a bogus "what it should be" auth key without ever getting back the
actual key generated by majordomo?

If this is the case there should probably be a patch written to replace the
algorithm if there isn't one already.  I can see this quickly reducing a large
number of lists to complete unusability.

-- 
::: Lazlo (lazlo@swcp.com; http://www.swcp.com/lazlo)
::: Internet Music Wantlists: http://www.swcp.com/lazlo/Wantlists


Follow-Ups:
Indexed By Date Previous: Re: mail queue
From: Jason L Tibbitts III <tibbs@hpc.uh.edu>
Next: Re: Malformed Headers...
From: Jason L Tibbitts III <tibbs@hpc.uh.edu>
Indexed By Thread Previous: Re: mail queue
From: Mats Dufberg <Mats.Dufberg@abc.se>
Next: Re: How secure is "+confirm"?
From: Jason L Tibbitts III <tibbs@hpc.uh.edu>

Google
 
Search Internet Search www.greatcircle.com