Great Circle Associates Majordomo-Users
(November 2000)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Approval passwords showing in digests
From: Dan Liston <dliston @ netscape . com>
Organization: iPlanet E-Commerce Solutions, A Sun Netscape Alliance
Date: Wed, 01 Nov 2000 17:45:16 -0600
To: Brad Hudson <bhudson @ creativityplus . com>
Cc: majordomo-users @ GreatCircle . COM
References: <4.2.0.58.20001030105601.00a44ab0@192.168.4.240> <4.2.0.58.20001101144510.00a40280@192.168.4.240>

I would recommend moving your brad-test-digestify off of your list 
address (brad-test) and onto your delivery address (brad-test-list).  
That way, nothing gets into your digest that does not go out to the 
regular list.

brad-test: "|/usr/lib/majordomo/wrapper resend -l brad-test brad-test-list,nobody"
brad-test-list: :include:/var/lib/majordomo/lists/brad-test,brad-test-digestify

The ,nobody added inside the quotes of brad-test will hide your 
delivery alias from being exposed in the message headers, and BOUNCE 
messages are not delivered to the digestify address until after they 
have successfully passed through resend.

Dan Liston


Brad Hudson wrote:
> 
> I've tried all these things with no luck.  My aliases appear to be fine,
> and the digest setup is nothing fancy.  Putting BOUNCE into taboo_headers
> doesn't help at all, the messages still show in the digest.  I have
> verified that the approved messages appear in the non-digest list properly.
> 
> I am using majordomo majordomo-1.94.4-8 (rpm version) under RedHat 6.0 on a
> sparc.
> 
> Here's how my aliases look for both lists:
> 
> List: brad-test
> 
> brad-test: "|/usr/lib/majordomo/wrapper resend -l brad-test
> brad-test-list",brad-test-digestify
> brad-test-list: :include:/var/lib/majordomo/lists/brad-test
> owner-brad-test: bhudson@godspeak.org
> brad-test-owner: bhudson@godspeak.org
> brad-test-approval: bhudson@godspeak.org
> brad-test-request: "|/usr/lib/majordomo/wrapper majordomo -l brad-test"
> 
> List: brad-test-digest
> 
> brad-test-digestify: "|/usr/lib/majordomo/wrapper digest -r -C -l
> brad-test-digest brad-test-digest-outgoing"
> brad-test-digest: brad-test
> brad-test-digest-outgoing: :include:/var/lib/majordomo/lists/brad-test-digest
> owner-brad-test-digest: bhudson@godspeak.org
> owner-brad-test-digest-outgoing: bhudson@godspeak.org
> brad-test-digest-owner: bhudson@godspeak.org
> brad-test-digest-approval: bhudson@godspeak.org
> brad-test-digest-request: "|/usr/lib/majordomo/wrapper majordomo -l
> brad-test-digest"
> 
> I have tried the following taboo_header lines in both brad-test.config and
> brad-test-digest.config (one at a time):
> 
> /BOUNCE/i
> /^subject:\s*BOUNCE/
> /^subject:\s*BOUNCE/i
> /^subject:\s.*BOUNCE/
> /^subject:\s.*BOUNCE/i
> 
> The taboo_header doesn't seem to apply when the message has already been
> approved.
> 
> I have personally been testing this and use Eudora, and I send everything
> in plain text only (as everyone should :) ).
> 
> I have noted that the approval message appears in the digest directly AFTER
> the good version of the same message.
> 
> I'm about at my wits end with this.  Is there something obious here that
> I'm missing?
> 
> Thanks;
> 
> Brad
> 
> At 08:19 AM 10/31/00 -0600, Dan Liston wrote:
> >One, you may want to put a filter in place that will bounce the offending
> >messages back to the list owner before they get distributed to the list.
> >
> >Two, make sure whoever is doing the approving is not sending the approved
> >message in MIME, HTML, or other non-pure ASCII text.
> >
> >Three, in your *-digest.config files, set up a filter to catch BOUNCE.  On
> >the other hand, if it got into the digest, I can just about guarantee that
> >it got into the "regular" list too.
> >
> >Dan Liston
> >
> >Brad Hudson wrote:
> > >
> > > Hey All;
> > >
> > > I have an odd problem I was hoping someone could help with.
> > >
> > > We have about 20 lists here which all have digests.  When the digests are
> > > sent, some of the messages in them show the "approved: password" line in
> > > the message; they also show the majordomo headers such as the "BOUNCE"
> > > subject line et al.  This is obviously a security problem.
> > >
> > > My initial investigation pointed to variations in the subject line of the
> > > approval message (ie: a (fwd) appended at the end of the subject), but this
> > > does not always seem to be the case.
> > >
> > > Can anyone shed some light on why this might be happening?
> > >
> > > Thanks,
> > >
> > > Brad



Follow-Ups:
References:
Indexed By Date Previous: Re: Digest difficulty
From: Dan Liston <dliston@netscape.com>
Next: Re: Precedence in every email body
From: John W Baxter <jwblist@olympus.net>
Indexed By Thread Previous: Re: Approval passwords showing in digests
From: Brad Hudson <bhudson@creativityplus.com>
Next: Re: Approval passwords showing in digests
From: Brad Hudson <bhudson@creativityplus.com>

Google
 
Search Internet Search www.greatcircle.com