Great Circle Associates Majordomo-Users
(April 2004)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Security hole
From: Rainer Sokoll <R . Sokoll @ intershop . de>
Date: Thu, 1 Apr 2004 13:55:04 +0200
To: mp @ gtt-technologies . de
Cc: Rainer Sokoll <R . Sokoll @ intershop . de>,majordomo-users @ greatcircle . com
In-reply-to: <406C19D8.9458.C87F86@localhost>
References: <406C0770.21838.80990D@localhost> <406C19D8.9458.C87F86@localhost>
User-agent: Mutt/1.4i

On Thu, Apr 01, 2004 at 01:32:08PM +0200, mp@gtt-technologies.de wrote:

Hi,

> > But this is a problem of a clueless configured virus scanner on the
> > remote side.
> > First, it makes no sense to send a warning out to the "sender", since
> > the "sender" is faked in almost all cases.
> This is only the case in recent times.

We /do/ have recent times ;-)

> > Second, even /if/ they send a warning, this warning shoud be addressed
> > neither to the From nor to the Reply-To, but to the Sender (which should
> > be somthing like majordomo-owner@listserver)
> This assumes that a mail server application is able to distinguish between
> a "normal" user address and a list server adress. I don't think this is
> the case and I presume it's too difficult to program.

I was wrong. If I understand RfC 821 correctly, error messages must
bounce back to the Envelope-From.
But again: These are usually faked nowadays.

Rainer
-- 
Stupidity is the basic building block of the universe.
                                         (Frank Zappa)


References:
Indexed By Date Previous: Re: Security hole
From: mp@gtt-technologies.de
Next: Re: security hole (not) - bounces
From: Frank Bax <fbax@sympatico.ca>
Indexed By Thread Previous: Re: Security hole
From: mp@gtt-technologies.de
Next: Re: Security hole
From: Daniel Liston <dliston@sonny.org>

Google
 
Search Internet Search www.greatcircle.com