Great Circle Associates Majordomo-Users
(March 2004)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: security hole
From: "Roger B.A. Klorese" <rogerk @ queernet . org>
Date: Sat, 27 Mar 2004 13:20:30 -0800
To: "MajorDomo Administrator, MSER:EX" <Majordomo . Admin @ gems1 . gov . bc . ca>
Cc: Majordomo-Users @ greatcircle . com
In-reply-to: <78C662A57529A14FAD49FC8819F5E2D40F6CE106@swan.bcsc.gov.bc.ca>
References: <78C662A57529A14FAD49FC8819F5E2D40F6CE106@swan.bcsc.gov.bc.ca>
User-agent: Mozilla Thunderbird 0.5+ (Windows/20040219)

MajorDomo Administrator, MSER:EX wrote:

> We noticed a bad security hole with our majordomo lists.  It was brought to
> our attention by the list subscribers who were getting spoofed virus
> rejections.  The rejections were going to the listname-outgoing address and
> therefore bypassing the requirement for moderation.
> 
> Has anyone else had this problem and how did they patch it?
> 
> a template of aliases file config
> 
> owner-l_tk_testlist: l_tk_testlist-owner
> l_tk_testlist: "|/home/majordomo/wrapper resend -l l_tk_testlist -h
> listsserver.ca -f l_tk_testlist-owner l_tk_testlist-outgoing"
> l_tk_testlist-owner: me@myaddress
> l_tk_testlist-approval: l_tk_testlist-owner
> owner-l_tk_testlist-approval: l_tk_testlist-owner
> l_tk_testlist-outgoing: :include:/home/majordomo/lists/l_tk_testlist
> owner-l_tk_testlist-outgoing: l_tk_testlist-owner
> 
> Thanks,
> Majordomo Support   
> mailto:Majordomo.Admin@gems1.gov.bc.ca
> 

Yes, many people have observed it.

And they've put the answer in the FAQ and the list archives.

Try those two locations and see if you can find it.




References:
  • security hole
    From: "MajorDomo Administrator, MSER:EX" <Majordomo.Admin@gems1.gov.bc.ca>
Indexed By Date Previous: Re: security hole
From: John Sechrest <sechrest@peak.org>
Next: Wholesale blacklisting by AHBL
From: "Ed Gregory" <ed@gregorynet.net>
Indexed By Thread Previous: Re: security hole
From: John Sechrest <sechrest@peak.org>
Next: Wholesale blacklisting by AHBL
From: "Ed Gregory" <ed@gregorynet.net>

Google
 
Search Internet Search www.greatcircle.com