Great Circle Associates Majordomo-Workers
(April 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: "resend" using files instead of outgoing-list-name
From: Mats Dufberg <Mats . Dufberg @ abc . se>
Date: Fri, 17 Apr 1998 15:46:50 +0100 (MET)
To: Michael Slavitch <slavitch @ loran . com>
Cc: majordomo-workers @ GreatCircle . COM, majordomo-users @ GreatCircle . COM
In-reply-to: <199804162131.RAA13056@elvis.loran.com>

On Thu, 16 Apr 1998, Michael Slavitch wrote:

> The following patch changes resend to close a security hole
> in closed lists. Using resend like this:
> 
> | /usr/local/majordomo/wrapper resend -l list outgoing-list
> 
> meant that outgoing-list was a valid alias that the outside world
> could mail to. Worse, the alias appeared in mail headers.


Is the patch really needed? This is from the FAQ:

   Sendmail 8.x will unfortunately log your -outgoing alias in the
   "Received:" lines. To prevent this you need to specify more than one
   address for the list name argument to resend. (for example
   "mylist:|"/usr/local/lib/majordomo/wrapper resend -h foo.org -l mylist
   mylist-seekrit,nobody"" where nobody is an alias for /dev/null) For
   Sendmail 8.x you must not define an alias 'owner-mylist-seekrit' to be
   something like 'owner-mylist,' (with the commma). Otherwise sendmail
   will set the envelope address of outgoing mail to contain your secret
   outgoing alias.

-----------------------------------------------------------------
Mats Dufberg                                  Mats.Dufberg@abc.se




Follow-Ups:
References:
Indexed By Date Previous: Re: What's going on in the area on i18n?
From: Norbert Bollow <nb@thinkcoach.com>
Next: Re: "resend" using files instead of outgoing-list-name
From: Michael Slavitch <slavitch@loran.com>
Indexed By Thread Previous: Re: "resend" using files instead of outgoing-list-name
From: Bonnie Scott <bonnie@ans.net>
Next: Re: "resend" using files instead of outgoing-list-name
From: Michael Slavitch <slavitch@loran.com>

Google
 
Search Internet Search www.greatcircle.com