Great Circle Associates Majordomo-Users
(September 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: majordomo-<listname>-outgoing
From: Leon Rothenberg <leon . rothenberg @ ctg . com>
Organization: Computer Task Group
Date: Tue, 01 Sep 1998 11:17:00 -0400
To: majordomo-users @ greatcircle . com
References: <Pine.BSI.3.91.980901031101.1040F-100000@packfish.gateway.net.hk>

Rino Lam wrote:
> 
> today.  Somebody tried to post a message to the address
> majordomo-<listname>-outgoing@mydomain directly, instead of the
> traditional default list address <listname>@mydomain.  The setting
> 

I have just encountered the same problem while testing/reconfiguring a
list.

       test:    "|/usr/test/majordomo-1.94.3/wrapper resend -l test
test-list"
       test-list:  :include:/usr/test/majordomo-1.94.3/lists/test
       owner-test:   you,
       test-owner:   you
       test-request: "|/usr/test/majordomo-1.94.3/wrapper majordomo -l
test"

This example, taken from the 'newlist' file shows a properly configured
set of aliases, however the alias "test-list" seems to be a fairly
obvious opportunity for spam exploitation.  It bypasses resend and our
dear <list>.config settings.  The only solution I can think of off the
top of my head is to make the ":include:" alias something cryptic, so
that potential spammers would have trouble guessing it:

       test:    "|/usr/test/majordomo-1.94.3/wrapper resend -l test
test-zzoutgo898"
       test-zzoutgo898:  :include:/usr/test/majordomo-1.94.3/lists/test

Are we missing something obvious here?

-- 
Leon Rothenberg
Mission Critical Systems, 
Computer Task Group


Follow-Ups:
Indexed By Date Previous: Re: reply-to dont work :(
From: Jeffrey Goldberg <J.Goldberg@Cranfield.ac.uk>
Next: Re: majordomo-<listname>-outgoing
From: "Roger B.A. Klorese" <rogerk@QueerNet.ORG>
Indexed By Thread Previous: Re: majordomo-<listname>-outgoing
From: Marc.Haber-lists@gmx.de (Marc Haber)
Next: Re: majordomo-<listname>-outgoing
From: "Roger B.A. Klorese" <rogerk@QueerNet.ORG>

Google
 
Search Internet Search www.greatcircle.com